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Abstract: Assume that each object in a database has m grades, or scores, one for each of m attributes. For 
example, an object can have a color grade, that tells how red it is, and a shape grade, that tells how round it is. 
For each attribute, there is a sorted list, which lists each object and its grade under that attribute, sorted by grade 
(highest grade first). Each object is assigned an overall grade, that is obtained by combining the attribute grades 
using a fixed monotone aggregation function, or combining rule, such as min or average. 

To determine the top k objects, that is, k objects with the highest overall grades, the naive algorithm must 
access every object in the database, to find its grade under each attribute. Fagin has given an algorithm ("Fagin's 
Algorithm", or FA) that is much more efficient. For some monotone aggregation functions, FA is optimal with 
high probability in the worst case. 

We analyze an elegant and remarkably simple algorithm ("the threshold algorithm", or TA) that is optimal in 
a much stronger sense than FA. We show that TA is essentially optimal, not just for some monotone aggregation 
functions, but for all of them, and not just in a high-probability worst-case sense, but over every database. Unlike 
FA, which requires large buffers (whose size may grow unboundedly as the database size grows), TA requires 
only a small, constant-size buffer. TA allows early stopping, which yields, in a precise sense, an approximate 
version of the top k answers. 

We distinguish two types of access: sorted access (where the middleware system obtains the grade of an 
object in some sorted list by proceeding through the list sequentially from the top), and random access (where the 
middleware system requests the grade of object in a list, and obtains it in one step). We consider the scenarios 
where random access is either impossible, or expensive relative to sorted access, and provide algorithms that are 
essentially optimal for these cases as well. 
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1 Introduction 



Early database systems were required to store only small character strings, such as the entries in a tuple 
in a traditional relational database. Thus, the data was quite homogeneous. Today, we wish for our 
database systems to be able to deal not only with character strings (both small and large), but also with 
a heterogeneous variety of multimedia data (such as images, video, and audio). Furthermore, the data 
that we wish to access and combine may reside in a variety of data repositories, and we may want our 
database system to serve as middleware that can access such data. 

One fundamental difference between small character strings and multimedia data is that multimedia 
data may have attributes that are inherently fuzzy. For example, we do not say that a given image is 
simply either "red" or "not red". Instead, there is a degree of redness, which ranges between (not at 
all red) and 1 (totally red). 

One approach [?] to deal with such fuzzy data is to make use of an aggregation function t. If 
xi, . . . , Xm (each in the interval [0, 1]) are the grades of object R under the m attributes, then t{xi, . . . , Xm) 
is the (overall) grade of object R. We shall often abuse notation and write t{R) for the grade t{xi , . . . , Xm) 
of R. As we shall discuss, such aggregation functions are useful in other contexts as well. There is a 
large literature on choices for the aggregation function (see Zimmermann's textbook [?] and the discus- 
sion in [?]). 

One popular choice for the aggregation function is min. In fact, under the standard rules of fuzzy 
logic [?], if object R has grade xi under attribute Ai and X2 under attribute A2, then the grade under the 
fuzzy conjunction Ai A A2 is min(3;i, j;2)- Another popular aggregation function is the average (or the 
sum, in contexts where we do not care if the resulting overall grade no longer lies in the interval [0, 1]). 

We say that an aggregation function t is monotone if t{xi, . . . , Xm) < t{x[, . . . , x'^) whenever 
< x'^ for every i. Certainly mono tonicity is a reasonable property to demand of an aggregation 

function: if for every attribute, the grade of object R' is at least as high as that of object R, then we 

would expect the overall grade of R' to be at least as high as that of R. 

The notion of a query is different in a multimedia database system than in a traditional database 
system. Given a query in a traditional database system (such as a relational database system), there 
is an unordered set of answers.]^ By contrast, in a multimedia database system, the answer to a query 
is a "graded" (or "fuzzy") set [?]. A graded set is a set of pairs {x,g), where x is an object, and g 
(the grade) is a real number in the interval [0, 1]. Graded sets are usually presented in sorted order, 
sorted by grade. As in [?], we shall identify a query with a choice of the aggregation function t. The 
user is typically interested in finding the top k answers, where A; is a given parameter (such as k = 1, 
k = W, or k = 100). This means that we want to obtain k objects (which we may refer to as the "top 
k objects") with the highest grades on this query, each along with its grade (ties are broken arbitrarily). 
For convenience, throughout this paper we will think of /c as a constant value, and we will consider 
algorithms for obtaining the top k answers in databases that contain at least k objects. 

Other applications: There are other applications besides multimedia databases where we make 
use of an aggregation function to combine grades, and where we want to find the top k answers. One 
important example is information retrieval [?], where the objects R of interest are documents, the m 
attributes are search terms sx, . . . , Sm, and the grade xi measures the relevance of document R for 

' Of course, in a relational database, the result to a query may be sorted in some way for convenience in presentation, 
such as sorting department members by salary, but logically speaking, the result is still simply a set, with a crisply-defined 
collection of members. 
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search term Sj, for 1 < z < m. It is common to take the aggregation function t to be the sum. That is, 
the total relevance score of document R when the query consists of the search terms si, . . . , is taken 

to be t{xi, . . . ,Xm) = Xi-[ h Xm- 

Another application arises in a paper by Aksoy and Franklin [?] on scheduling large-scale on- 
demand data broadcast. In this case each object is a page, and there are two fields. The first field repre- 
sents the amount of time waited by the earliest user requesting a page, and the second field represents 
the number of users requesting a page. They make use of the product function t with t{xi,X2) = xiX2, 
and they wish to broadcast next the page with the top score. 

The model: We assume that each database consists of a finite set of objects. We shall typically take 
N to represent the number of objects. Associated with each object R arc TTi fields X]^, . . . , Xui, where 
Xi G [0, 1] for each i. We may refer to Xi as the ith field of R. The database can be thought of as 
consisting of a single relation, where one column corresponds to the object id, and the other columns 
correspond to m attributes of the object. Alternatively, the way we shall think of a database in this paper 
is as consisting of m sorted lists Li, . . . , Lm, each of length N (there is one entry in each list for each 
of the N objects). We may refer to Lj as list i. Each entry of Lj is of the form {R, Xi), where Xi is the 
ith field of R. Each list Lj is sorted in descending order by the Xi value. We take this simple view of 
a database, since this view is all that is relevant, as far as our algorithms are concerned. We are taking 
into account only access costs, and ignoring internal computation costs. Thus, in practice it might well 
be expensive to compute the field values, but we ignore this issue here, and take the field values as being 
given. 

We consider two modes of access to data. The first mode of access is sorted (or sequential) access. 
Here the middleware system obtains the grade of an object in one of the sorted lists by proceeding 
through the list sequentially from the top. Thus, if object R has the £th highest grade in the ith list, then 
I sorted accesses to the ith list are required to see this grade under sorted access. The second mode of 
access is random access. Here, the middleware system requests the grade of object R in the ith list, and 
obtains it in one random access. If there are s sorted accesses and r random accesses, then the sorted 
access cost is scs, the random access cost is tcr, and the middleware cost is scs + rcR (the sum of the 
sorted access cost and the random access cost), for some positive constants cs and cr. 

Algorithms: There is an obvious naive algorithm for obtaining the top k answers. Under sorted 
access, it looks at every entry in each of the m sorted lists, computes (using t) the overall grade of every 
object, and returns the top k answers. The naive algorithm has linear middleware cost (linear in the 
database size), and thus is not efficient for a large database. 

Fagin [?] introduced an algorithm ("Fagin's Algorithm", or FA), which often does much better than 
the naive algorithm. In the case where the orderings in the sorted lists are probabilistically independent, 
FA finds the top k answers, over a database with objects, with middleware cost 0{N^'^^^^/'^k^/^), 
with arbitrarily high probability.^ Fagin also proved that under this independence assumption, along 
with an assumption on the aggregation function, every correct algorithm must, with high probability, 
incur a similar middleware cost in the worst case. 

We shall present the "threshold algorithm", or TA. This algorithm was discovered independently by 
(at least) three groups, including Nepal and Ramakrishna [?] (who were the first to publish), Giintzer, 
BaLke, and Kiessling [?], and ourselves.^ For more information and comparison, see Section [T^ on 

^We shall not discuss the probability model here, including the notion of "independence", since it is off track. For details, 
see [?]. 

^Our second author first defined TA, and did extensive simulations comparing it to FA, as a project in a database course 
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related work. 

We shall show that TA is optimal in a much stronger sense than FA. We now define this notion of 
optimality, which we consider to be interesting in its own right. 

Instance optimality: Let A be a class of algorithms, let D be a class of databases, and let cost{A, V) 
be the middleware cost incurred by running algorithm A over database V. We say that an algorithm B 
is instance optimal over A and D if ;B € A and if for every ^ G A and every P G D we have 

cost{B, V) = 0{cost{A, V)). (1) 

Equation (|l[) means that there are constants c and c' such that cost{B, T>) < c- cost{A, V) + c' for every 
choice of ^ € A and D € D. We refer to c as the optimality ratio. Intuitively, instance optimality 
corresponds to optimality in every instance, as opposed to just the worst case or the average case. 
FA is optimal in a high-probability worst-case sense under certain assumptions. TA is optimal in a 
much stronger sense, and without any underlying probabilistic model or probabilistic assumptions: it is 
instance optimal, for several natural choices of A and D. In particular, instance optimality holds when 
A is taken to be the class of algorithms that would normally be implemented in practice (since the only 
algorithms that are excluded are those that make very lucky guesses), and when D is taken to be the class 
of all databases. Instance optimality of TA holds in this case for all monotone aggregation functions. By 
contrast, high-probability worst-case optimality of FA holds only under the assumption of "strictness" 
(we shall define strictness later; intuitively, it means that the aggregation function is representing some 
notion of conjunction). 

Approximation and early stopping: There are times when the user may be satisfied with an ap- 
proximate top k list. Assume 6 > 1. Define a 6 -approximation to the top k answers for the aggregation 
function t to be a collection of k objects (each along with its grade) such that for each y among these k 
objects and each z not among these k objects, 9t{y) > t{z). Note that the same definition with 6 = 1 
gives the top k answers. We show how to modify TA to give such a ^-approximation (and prove the 
instance optimality of this modified algorithm under certain assumptions). In fact, we can easily modify 
TA into an interactive process where at all times the system can show the user its current view of the top 
k list along with a guarantee about the degree 9 of approximation to the correct answer. At any time, 
the user can decide, based on this guarantee, whether he would like to stop the process. 

Restricting random access: As we shall discuss in Section ^ there are some systems where random 
access is impossible. To deal with such situations, we show in Section ^j] how to modify TA to obtain an 
algorithm NRA ("no random accesses") that does no random accesses. We prove that NRA is instance 
optimal over all algorithms that do not make random accesses and over all databases. 

What about situations where random access is not impossible, but simply expensive? Wimmers et 
al. [?] discuss a number of systems issues that can cause random access to be expensive. Although 
TA is instance optimal, the optimality ratio depends on the ratio cr/cs of the cost of a single random 
access to the cost of a single sorted access. We define another algorithm that is a combination of TA 
and NRA, and call it CA ("combined algorithm"). The definition of the algorithm depends on cr/cs- 
The motivation is to obtain an algorithm that is not only instance optimal, but whose optimality ratio 
is independent of cr/cs- Our original hope was that CA would be instance optimal (with optimality 
ratio independent of cr/cs) in those scenarios where TA is instance optimal. Not only does this hope 
fail, but interestingly enough, we prove that there does not exist any deterministic algorithm, or even 

taught by Michael Frankhn at the University of Maryland-College Park, in the Fall of 1997. 
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probabilistic algorithm that does not make a mistake, with optimality ratio independent of cji/cs in 
these scenarios! However, we find a new natural scenario where CA is instance optimal, with optimality 
ratio independent oi cr/cs- 

Outline of paper: In Section ^, we discuss modes of access (sorted and random) to data. In Sec- 
tion |3[ we present FA (Fagin's Algorithm) and its properties. In Section 0, we present TA (the Threshold 
Algorithm). In Section we define instance optimality, and compare it with related notions, such as 
competitiveness. In Section ^ we show that TA is instance optimal in several natural scenarios. In the 
most important scenario, we show that the optimality ratio of TA is best possible. In Section 5. 1 , we dis- 
cuss the dependence of the optimality ratio on various parameters. In Section we show how to turn 
TA into an approximation algorithm, and prove instance optimality among approximation algorithms. 
We also show how the user can prematurely halt TA and in a precise sense, treat its current view of 
the top k answers as an approximate answer. In Section ^, we consider situations (suggested by Bruno, 
Gravano, and Marian [?]) where sorted access is impossible for certain of the sorted lists. In Section ^, 
we focus on situations where random accesses are either impossible or expensive. In Section 8.1 we 



present NRA (No Random Access algorithm), and show its instance optimality among algorithms that 
make no random accesses. Further, we show that the optimality ratio of NRA is best possible. In Sec- 
tion we present CA (Combined Algorithm), which is a result of combining TA and NRA in order to 
obtain an algorithm that, intuitively, minimizes random accesses. In Section 83, we show instance op- 
timality of CA, with an optimality ratio independent of cr/cs, in a natural scenario. In Section 8.4, we 



show that the careful choice made by CA of which random accesses to make is necessary for instance 
optimality with an optimality ratio independent of cr/cs- We also compare and contrast CA versus TA. 
In Section ^ we prove various lower bounds on the optimality ratio, both for deterministic algorithms 
and for probabilistic algorithms that never make a mistake. We summarize our upper and lower bounds 
in Section p?T| . In Section |l^ we discuss related work. In Section |ll|, we give our conclusions, and state 
some open problems. 



2 Modes of Access to Data 

Issues of efficient query evaluation in a middleware system are very different from those in a traditional 
database system. This is because the middleware system receives answers to queries from various 
subsystems, which can be accessed only in limited ways. What do we assume about the interface 
between a middleware system and a subsystem? Let us consider QBICQ [?] ("Query By Image Content") 
as a subsystem. QBIC can search for images by various visual characteristics such as color and texture 
(and an experimental version can search also by shape). In response to a query, such as Color='red' , 
the subsystem will output the graded set consisting of all objects, one by one, each along with its grade 
under the query, in sorted order based on grade, until the middleware system tells the subsystem to halt. 
Then the middleware system could later tell the subsystem to resume outputting the graded set where 
it left off. Alternatively, the middleware system could ask the subsystem for, say, the top 10 objects in 
sorted order, each along with its grade, then request the next 10, etc. In both cases, this corresponds to 
what we have referred to as "sorted access". 

There is another way that we might expect the middleware system to interact with the subsystem. 
Specifically, the middleware system might ask the subsystem for the grade (with respect to a query) 

''QBIC is a trademark of IBM Corporation. 
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of any given object. This corresponds to what we have referred to as "random access". In fact, QBIC 
allows both sorted and random access. 

There are some situations where the middleware system is not allowed random access to some 
subsystem. An example might occur when the middleware system is a text retrieval system, and the 
subsystems are search engines. Thus, there does not seem to be a way to ask a major search engine on 
the web for its internal score on some document of our choice under a query. 

Our measure of cost corresponds intuitively to the cost incurred by the middleware system in pro- 
cessing information passed to it from a subsystem such as QBIC. As before, if there are s sorted accesses 
and r random accesses, then the middleware cost is taken to be scs + rcR, for some positive constants 
cs and cr. The fact that cs and cr may be different reflects the fact that the cost to a middleware system 
of a sorted access and of a random access may be different. 

3 Fagin's Algorithm 

In this section, we discuss FA (Fagin's Algorithm) [?].This algorithm is implemented in Garlic [?], 
an experimental IBM middleware system; see [?] for interesting details about the implementation and 
performance in practice. Chaudhuri and Gravano [?] consider ways to simulate FA by using "filter 
conditions", which might say, for example, that the color score is at least 0.2.^ FA works as follows. 

1. Do sorted access in parallel to each of the m sorted lists Lj. (By "in parallel", we mean that we 
access the top member of each of the lists under sorted access, then we access the second member 
of each of the lists, and so on.)^ Wait until there are at least k "matches", that is, wait until there 
is a set H of at least k objects such that each of these objects has been seen in each of the m lists. 

2. For each object R that has been seen, do random access as needed to each of the lists L,; to find 
the ith field Xi of R. 

3. Compute the grade t{R) = t{xi, . . . , Xm) for each object R that has been seen. Let y be a set 
containing the k objects that have been seen with the highest grades (ties are broken arbitrarily). 
The output is then the graded set {{R, t{R)) \ R eY}. 

It is fairly easy to show [?] that this algorithm is correct for monotone aggregation functions t (that 
is, that the algorithm successfully finds the top k answers). If there are N objects in the database, and 
if the orderings in the sorted lists are probabilistically independent, then the middleware cost of FA is 
0(Ar(m-i)/™yti/™)^ ^jth arbitrarily high probability [?]. 

An aggregation function t is strict [?] if t{xi, . . . ,Xm) = 1 holds precisely when Xi = 1 for 
every i. Thus, an aggregation function is strict if it takes on the maximal value of 1 precisely when each 
argument takes on this maximal value. We would certainly expect an aggregation function representing 

^Chaudhuri and Gravano originally saw an early version of the conference paper (in the 1996 ACM Symposium on Princi- 
ples of Database Systems) that expanded into the journal version [?]. 

*It is not actually important that the lists be accessed "in lockstep". In practice, it may be convenient to allow the sorted lists 
to be accessed at different rates, in batches, etc. Each of the algorithms in this paper where there is "sorted access in parallel" 
remain correct even when sorted access is not in lockstep. Furthermore, all of our instance optimality results continue to hold 
even when sorted access is not in lockstep, as long as the rates of sorted access of the lists are within constant multiples of 
each other. 
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the conjunction to be strict (see the discussion in [?]). In fact, it is reasonable to think of strictness as 
being a key characterizing feature of the conjunction. 

Fagin shows that his algorithm is optimal with high probability in the worst case if the aggregation 
function is strict (so that, intuitively, we are dealing with a notion of conjunction), and if the orderings 
in the sorted lists are probabilistically independent. In fact, the access pattern of FA is oblivious to the 
choice of aggregation function, and so for each fixed database, the middleware cost of FA is exactly the 
same no matter what the aggregation function is. This is true even for a constant aggregation function; 
in this case, of course, there is a trivial algorithm that gives us the top k answers (any k objects will do) 
with 0(1) middleware cost. So FA is not optimal in any sense for some monotone aggregation functions 
t. As a more interesting example, when the aggregation function is max (which is not strict), it is shown 
in [?] that there is a simple algorithm that makes at most mk sorted accesses and no random accesses 
that finds the top k answers. By contrast, as we shall see, the algorithm TA is instance optimal for every 
monotone aggregation function, under very weak assumptions. 

Even in the cases where FA is optimal, this optimality holds only in the worst case, with high proba- 
bility. This leaves open the possibility that there are some algorithms that have much better middleware 
cost than FA over certain databases. The algorithm TA, which we now discuss, is such an algorithm. 

4 The Threshold Algorithm 

We now present the threshold algorithm (TA). 

1. Do sorted access in parallel to each of the m sorted lists Lj. As an object R is seen under sorted 
access in some list, do random access to the other lists to find the grade x-i of object R in every 
list Li.|] Then compute the grade t{R) = t{xi, . . . , Xm) of object R. If this grade is one of the k 
highest we have seen, then remember object R and its grade t{R) (ties are broken arbitrarily, so 
that only k objects and their grades need to be remembered at any time). 

2. For each list Lj, let x^ be the grade of the last object seen under sorted access. Define the threshold 
value T to be t{xi, . . . ,x^). As soon as at least k objects have been seen whose grade is at least 
equal to r, then halt. 

3. Let y be a set containing the k objects that have been seen with the highest grades. The output is 
then the graded set {{R, t{R)) \ R£Y}. 

We now show that TA is correct for each monotone aggregation function t. 

Theorem 4.1: If the aggregation function t is monotone, then TA correctly finds the top k answers. 

Proof: Let Y be as in Step 3 of TA. We need only show that every member of Y has at least as high a 
grade as every object z not in Y . By definition of Y, this is the case for each object z that has been seen 
in running TA. So assume that z was not seen. Assume that the fields of Therefore, 
< for every i. Hence, t{z) = t{xi, . . . , Xm) < ■ ■ ■ ^^Im) = where the inequality follows 

'it may seem wasteful to do random access to find a grade that was already determined earlier. As we discuss later, this is 
done in order to avoid unbounded buffers. 
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by monotonicity of t. But by definition of Y, for every y in y we have t{y) > r. Therefore, for every y 
in Y we have t{y) > r > t{z), as desired. □ 

We now show that the stopping rule for TA always occurs at least as early as the stopping rule for 
FA (that is, with no more sorted accesses than FA). In FA, if R is an object that has appeared under 
sorted access in every list, then by monotonicity, the grade of R is at least equal to the threshold value. 
Therefore, when there are at least k objects, each of which has appeared under sorted access in every 
list (the stopping rule for FA), there are at least k objects whose grade is at least equal to the threshold 
value (the stopping rule for TA). 

This implies that for every database, the sorted access cost for TA is at most that of FA. This does 
not imply that the middleware cost for TA is always at most that of FA, since TA may do more random 
accesses than FA. However, since the middleware cost of TA is at most the sorted access cost times a 
constant (independent of the database size), it does follow that the middleware cost of TA is at most a 
constant times that of FA. In fact, we shall show that TA is instance optimal, under natural assumptions. 

We now consider the intuition behind TA. For simplicity, we discuss first the case where k = 1, 
that is, where the user is trying to determine the top answer. Assume that we are at a stage in the 
algorithm where we have not yet seen any object whose (overall) grade is at least as big as the threshold 
value r. The intuition is that at this point, we do not know the top answer, since the next object we see 
under sorted access could have overall grade r, and hence bigger than the grade of any object seen so 
far. Furthermore, once we do see an object whose grade is at least r, then it is safe to halt, as we see 



from the proof of Theorem 11. Thus, intuitively, the stopping rule of TA says: "Halt as soon as you 
know you have seen the top answer." Similarly, for general k, the stopping rule of TA says, intuitively, 
"Halt as soon as you know you have seen the top k answers." So we could consider TA as being an 
implementation of the following "program": 

Do sorted access (and the corresponding random access) until you know you have seen the top k 
answers. 

This very high-level "program" is a knowledge-based program [?]. In fact, TA was designed by 
thinking in terms of this knowledge-based program. The fact that TA corresponds to this knowledge- 
based program is what is behind instance optimality of TA. 

Later, we shall give other scenarios (situations where random accesses are either impossible or 
expensive) where we implement the following more general knowledge-based program: 

Gather what information you need to allow you to know the top k answers, and then halt. 

In each of our scenarios, the implementation of this second knowledge-based program is different. When 
we consider the scenario where random accesses are expensive relative to sorted accesses, but are not 
impossible, we need an additional design principle to decide how to gather the information, in order to 
design an instance optimal algorithm. 

The next theorem, which follows immediately from the definition of TA, gives a simple but impor- 
tant property of TA that further distinguishes TA from FA. 

Theorem 4.2: TA requires only bounded buffers, whose size is independent of the size of the database. 
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Proof: Other than a little bit of bookkeeping, all that TA must remember is the current top k objects and 
their grades, and (pointers to) the last objects seen in sorted order in each list. □ 

By contrast, FA requires buffers that grow arbitrarily large as the database grows, since FA must 
remember every object it has seen in sorted order in every list, in order to check for matching objects in 
the various lists. 

There is a price to pay for the bounded buffers. Thus, for every time an object is found under sorted 
access, TA may do m — 1 random accesses (where m is the number of lists), to find the grade of the 
object in the other Usts. This is in spite of the fact that this object may have already been seen in these 
other lists. 

5 Instance optimality 

In order to compare instance optimality with other notions from the literature, we generalize slightly the 
definition from that given in the introduction. Let A be a class of algorithms, and let D be a class of 
legal inputs to the algorithms. We assume that we are considering a particular nonnegative performance 
cost measure cost {A, V), which represents the amount of a resource consumed by running the algorithm 
^ € A on input V £D. This cost could be the running time of algorithm A on input V, or in this paper, 
the middleware cost incurred by running algorithm A over database V. 

We say that an algorithm B is instance optimal over A and D if S G A and if for every ^ e A and 
every P G D we have 

cost{B, V) = 0{cost{A, V)). (2) 

Equation (^ means that there are constants c and c' such that cost{B, T>) < a- cost{A, V) + c' for every 
choice of ^ G A and P G D. We refer to c as the optimality ratio. It is similar to the competitive ratio 
in competitive analysis (we shall discuss competitive analysis shortly). We use the word "optimal" to 
reflect that fact that B is essentially the best algorithm in A. 

Intuitively, instance optimality corresponds to optimality in every instance, as opposed to just the 
worst case or the average case. There are many algorithms that are optimal in a worst-case sense, but 
are not instance optimal. An example is binary search: in the worst case, binary search is guaranteed to 
require no more than log N probes, for A'^ data items. However, for each instance, a positive answer can 
be obtained in one probe, and a negative answer in two probes. 

We consider a nondeterministic algorithm correct if on no branch does it make a mistake. We take 
the middleware cost of a nondeterministic algorithm to be the minimal cost over all branches where it 
halts with the top k answers. We take the middleware cost of a probabilistic algorithm to be the expected 
cost (over all probabilistic choices by the algorithm). When we say that a deterministic algorithm B 
is instance optimal over A and D, then we are really comparing B against the best nondeterministic 
algorithm, even if A contains only deterministic algorithms. This is because for each P G D, there is 
always a deterministic algorithm that makes the same choices on V as the nondeterministic algorithm. 
We can view the cost of the best nondeterministic algorithm that produces the top k answers over a given 
database as the cost of the shortest proof for that database that these are really the top k answers. So 
instance optimality is quite strong: the cost of an instance optimal algorithm is essentially the cost of the 
shortest proof. Similarly, we can view A as if it contains also probabilistic algorithms that never make 
a mistake. For convenience, in our proofs we shall always assume that A contains only deterministic 
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algorithms, since the results carry over automatically to nondeterministic algorithms and to probabiUstic 
algorithms that never make a mistake. 

The definition we have given for instance optimality is formally the same definition as is used in 
competitive analysis [?, ?], except that in competitive analysis, (1) we do not assume that ;B G A, and 
(2) cost{A, V) does not typically represent a performance cost. In competitive analysis, typically (a) D 
is a class of instances of a particular problem, (b) A is the class of offline algorithms that give a solution 
to the instances in D, (c) cost{A, V) is a number that represents the goodness of the solution (where 
bigger numbers correspond to a worse solution), and (d) B is a. particular online algorithm. In this case, 
the online algorithm B is said to be competitive. The intuition is that a competitive online algorithm 
may perform poorly in some instances, but only on instances where every offline algorithm would also 
perform poorly. 

Another example where the framework of instance optimality appears, but again without the as- 
sumption that ;S G A, and again where cost{A, V) does not represent a performance cost, is in the 
context of approximation algorithms [?]. In this case, (a) D is a class of instances of a particular prob- 
lem, (b) A is the class of algorithms that solve the instances in D exactly (in cases of interest, these 
algorithms are not polynomial-time algorithms), (c) cost{A, V) is the value of the resulting answer 
when algorithm A is applied to input V, and (d) 5 is a particular polynomial-time algorithm. 

Dagum et al. [?] give an interesting example of what we would call an instance optimal algorithm. 
They consider the problem of determining the mean of an unknown random variable by Monte Carlo 
estimation. In their case, (a) D is the class of random variables distributed in the interval [0, 1], (b) A 
is the class of algorithms that, by repeatedly doing independent evaluations of a random variable and 
then averaging the results, obtain an estimate of the mean of the random variable to within a given 
precision with a given probability, (c) cost{A., V) is the expected number of independent evaluations 
of the random variable V under algorithm A, and (d) B is their algorithm, which they call AA for 
"approximation algorithm". Their main result says, in our terminology, that AA is instance optimal 
over A and D. 

Demaine et al. [?] give an example of an algorithm that is close to instance optimal. They consider 
the problem of finding the intersection, union, or difference of a collection of sorted sets. In their case, 
(a) D is the class of instances of collections of sorted sets, (b) A is the class of algorithms that do 
pairwise comparisons among elements, (c) cost{A, V) is the running time (number of comparisons) in 
running algorithm A on instance T>, and (d) B is their algorithm. In a certain sense, their algorithm is 
close to what we would call instance optimal (to explain the details would take us too far astray). 

6 Instance Optimality of the Threshold Algorithm 

In this section, we investigate the instance optimality of TA. We begin with an intuitive argument that 
TA is instance optimal. If A is an algorithm that stops sooner than TA on some database, before A 
finds k objects whose grade is at least equal to the threshold value r, then A must make a mistake on 
some database, since the next object in each list might have grade in each list i, and hence have grade 
t{xi , . . . , x„^) = T. This new object, which A has not even seen, has a higher grade than some object in 
the top k list that was output by A, and so A erred by stopping too soon. We would like to convert this 
intuitive argument into a proof that for every monotone aggregation function, TA is instance optimal 
over all algorithms that correctly find the top k answers, over the class of all databases. However, as we 
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shall see, the situation is actually somewhat delicate. We first make a distinction between algorithms that 
"make wild guesses" (that is, perform random access on objects not previously encountered by sorted 
access) and those that do not. (Neither FA nor TA make wild guesses, nor does any "natural" algorithm 
in our context.) Our first theorem (Theorem ^) says that for every monotone aggregation function, TA 
is instance optimal over all algorithms that correctly find the top k answers and that do not make wUd 
guesses, over the class of all databases. We then show that this distinction (wild guesses vs. no wild 
guesses) is essential: if algorithms that make wild guesses are allowed in the class A of algorithms that 
an instance optimal algorithm must compete against, then no algorithm is instance optimal (Example E3| 



and Theorem |6.4j). The heart of this example (and the corresponding theorem) is the fact that there may 
be multiple objects with the same grade in some list. Indeed, once we restrict our attention to databases 
where no two objects have the same value in the same list, and make a slight, natural additional restric- 
tion on the aggregation function beyond monotonicity, then TA is instance optimal over all algorithms 
that correctly find the top k answers (Theorem 6.5). 

In Section we consider instance optimality in the situation where we relax the problem of finding 
the top k objects into finding approximately the top k. 

We now give our first positive result on instance optimality of TA. We say that an algorithm makes 
wild guesses if it does random access to find the grade of some object R in some list before the algorithm 
has seen R under sorted access. That is, an algorithm makes wild guesses if the first grade that it obtains 
for some object R is under random access. We would not normally implement algorithms that make 
wild guesses. In fact, there are some contexts where it would not even be possible to make wild guesses 
(such as a database context where the algorithm could not know the name of an object it has not already 
seen). However, making a lucky wild guess can help, as we show later (Example 6.3 ). 

We now show instance optimality of TA among algorithms that do not make wild guesses. In this 
theorem, when we take D to be the class of all databases, we really mean that D is the class of all 
databases that involve sorted lists corresponding to the arguments of the aggregation function t. We are 
taking k (where we are trying to find the top k answers) and the aggregation function t to be fixed. Since 
we are taking t to be fixed, we are thereby taking the number m of arguments of t (that is, the number 
of sorted lists) to be fixed. In Section 6.1, we discuss the assumptions that k and m are constant. 



Theorem 6.1: Assume that the aggregation function t is monotone. Let D be the class of all databases. 
Let A be the class of all algorithms that correctly find the top k answers for t for every database and 
that do not make wild guesses. Then TA is instance optimal over A and D. 

Proof: Assume that ^ G A, and that algorithm A is run over database V. Assume that algorithm 
A halts at depth d (that is, if di is the number of objects seen under sorted access to list i, for 1 < 
i < m, then d = max, di). Assume that A sees a distinct objects (some possibly multiple times). In 
particular, a > d. Since A makes no wild guesses, and sees a distinct objects, it must make at least a 
sorted accesses, and so its middleware cost is at least acs. We shall show that TA halts on V by depth 
a + k. Hence, the middleware cost of TA is at most (a + k)mcs + (a + k)m{m — 1)cr, which is 
amcs + am{m — 1)cr plus an additive constant of kmcs + km{m — 1)cr. So the optimality ratio of 
TA is at most '^'-^^s+am(m-i)cR = rn{m - 1)cr/cs. (Later, we shall show that if the aggregation 
function is strict, then this is precisely the optimality ratio of TA, and this is best possible.) 

Note that for each choice of d', the algorithm TA sees at least d' objects by depth d' (this is because 
by depth d' it has made md' sorted accesses, and each object is accessed at most m times under sorted 
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access). Let Y be the output set of A (consisting of the top k objects). If there are at most k objects 
that A does not see, then TA halts by depth a + k (after having seen every object), and we are done. So 
assume that there are at least A; + 1 objects that A does not see. Since Y is of size k, there is some object 
V that A does not see and that is not in Y. 

Let be the threshold value when algorithm A halts. This means that if Xj is the grade of the last 
object seen under sorted access to list i for algorithm ^, for 1 < i < m, then r_4 = t{xi, . . . ,x^). (If 
list i is not accessed under sorted access, we take Xj = 1.) Let us call an object R big if t{R) > t_a, and 
otherwise call object R small. 

We now show that every member ii of y is big. Define a database V to be just like V, except that 
object V has grade Xj in the zth list, for 1 < i < m. Put V in list i below all other objects with grade 
Xj in list i (for 1 < i < m). Algorithm A performs exactly the same, and in particular gives the same 
output, for databases V and V . Therefore, algorithm A has R, but not V , in its output for database V . 
Since the grade of V in V is r^, it follows by correctness of A that R is big, as desired. 

There are now two cases, depending on whether or not algorithm A sees every member of its output 
setyj] 

Case 1: Algorithm A sees every member of Y. Then by depth d, TA will see every member of Y. 
Since, as we showed, each member of Y is big, it follows that TA halts by depth d < a < a + k, as 
desired. 

Case 2: Algorithm A does not see some member R of Y. We now show that every object R' that 
is not seen by A must be big. Define a database V that is just like V on every object seen by A. Let 
the grade of V in list f be Xj, and put V in list i below all other objects with grade Xj in list i (for 
1 < i < m). Therefore, the grade of V in database V is r_4. Since A cannot distinguish between V 
and V, it has the same output on V and V. Since A does not see R and does not see R', it has no 
information to distinguish between R and R'. Therefore, it must have been able to give R' in its output 
without making a mistake. But if R' is in the output and not V, then by correctness of A, it follows that 
R' is big. So R' is big, as desired. 

Since A sees a objects, and since TA sees at least a + k objects by depth a + k, it follows that by 
depth a + k, TA sees at least k objects not seen by A. We have shown that every object that is not seen 
by A is big. Therefore, by depth a + k, TA sees at least k big objects. So TA halts by depth a + k, as 
desired. □ 

The next result is a corollary of the proof of Theorem ^ and of a lower bound in Section ^ (all 
of our results on lower bounds appear in Secti on ^ . Specifically, in the proof of Theorem ^H] , we 
showed that under the assumptions of Theorem |6. iR no wild guesses), the optimality ratio of TA is at 
most m + m(m — 1)cr/cs- The next result says that if the aggregation function is strict, then the 
optimality ratio is precisely this value, and this is best possible. Recall that an aggregation function t is 
strict if t(xi, . . . , Xm) = 1 holds precisely when Xj = 1 for every i. Intuitively, strictness means that 
the aggregation function is representing some notion of conjunction. 

Corollary 6.2: Let t be an arbitrary monotone, strict aggregation function with m arguments. Let D be 
the class of all databases. Let A be the class of all algorithms that correctly find the top k answers for t 
for every database and that do not make wild guesses. Then TA is instance optimal over A and D, with 
optimality ratio m + m{m — 1)cr/cs- No deterministic algorithm has a lower optimality ratio. 

'^For the sake of generality, we are allowing the possibility that algorithm A can output an object that it has not seen. We 
discuss this issue more in Section b.ll 
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Figure 1 : Database for Example 



Proof: In the proof of Theorem |6.1| , it is shown that TA has an optimality ratio of at most m + m{m — 
1)cr/cs for an arbitrary monotone aggregation function, The lower bound follows from Theorem p?l| . 
□ 

We cannot drop the assumption of strictness in Corollary For example, let the aggregation 
function be max (which is not strict). It is easy to see that TA halts after k rounds of sorted access, and 
its optimality ratio is m (which, we might add, is best possible for max).[| 

What if we were to consider only the sorted access cost? This corresponds to taking cr = 0. Then 



we see from Corollary |6^ that the optimality ratio of TA is m. Furthermore, it follows easily from the 
proof of Theorem ^[l| that if the aggregation function is strict, and if c/j = 0, then this is best possible: 
no deterministic algorithm has a lower optimality ratio than m.^ 

What if we were to consider only the random access cost? This corresponds to taking cs = 0. In 
this case, TA is far from instance optimal. The naive algorithm, which does sorted access to every object 
in every list, does no random accesses, and so has a sorted access cost of 0. 

We now show that making a lucky wild guess can help. 

Example 6.3: Assume that there are 2n + l objects, which we will call simply 1, 2, . . . , 2n + l, and there 
are two lists Li and L2 (see Figure |l|). Assume that in list Li, the objects are in the order 1, 2, . . . , 2n + 

1, where the top n + 1 objects 1, 2, . . . , n + 1 all have grade 1, and the remaining n objects n + 

2, n + 3, . . . , 2n + 1 all have grade 0. Assume that in list L2, the objects are in the reverse order 
2n + 1, 2n, . . . , 1, where the bottom n objects 1, . . . , n all have grade 0, and the remaining n + 1 objects 
n + 1, n + 2, . . . , 2n + 1 all have grade 1. Assume that the aggregation function is min, and that we 
are interested in finding the top answer (i.e., k = 1). It is clear that the top answer is object n + 1 with 
overall grade 1 (every object except object n + 1 has overall grade 0). 

An algorithm that makes a wild guess and asks for the grade of object n + 1 in both Usts would 
determine the correct answer and be able to halt safely after two random accesses and no sorted ac- 

' Note that the instance optimahty of TA, as given by Theore m p. l| , holds whether or not the aggregation function is strict. 
For example, the instance optimality of TA as given by Theorem p. 1| holds even when the aggregation function is max. This is 
in contrast to the situation with FA, where high-probability worst-case optimality fails when the aggregation function is max. 



Corollary 5.2 makes use of the assumption of strictness only in order to show that the optimality ratio of TA is then precisely 



m + m(m — 1)cr/cs, and that this is best possible, 
'"We are assuming in this paper that cr and eg a 
rem would still hold if we were to allow cr to be 



'"We are assuming in this paper that cr and eg are both strictly positive. However, Corollary 16^ and the proof of Theo- 



12 



cesses.|^ However, let A be any algorithm (such as TA) that does not make wild guesses. Since the 
winning object n + 1 is in the middle of both sorted lists, it follows that at least n + 1 sorted accesses 
would be required before algorithm A would even see the winning object. □ 



What if we were to enlarge the class A of algorithms to allow queries of the form "Which object has 
the ith largest grade in list j, and what is its grade in list j?" We then see from Example 63, where we 
replace the wild guess by the query that asks for the object with the (n + l)st largest grade in each list, 
that TA is not instance optimal. Effectively, these new queries are "just as bad" as wild guesses. 

Example ^ shows that TA is not instance optimal over the class A of all algorithms that find the 
top answer for min (with two arguments) and the class D of all databases. The next theorem says that 
under these circumstances, not only is TA not instance optimal, but neither is any algorithm. 



Theorem 6.4: Let D be the class of all databases. Let A be the class of all algorithms that correctly find 
the top answer for min (with two arguments) for every database. There is no deterministic algorithm 
(or even probabilistic algorithm that never makes a mistake) that is instance optimal over A and D. 

Proof: Let us modify Example |6.3| to obtain a family of databases, each with two sorted hsts. The first 
list has the objects 1, 2, . . . , 2n + 1 in some order, with the top n + 1 objects having grade 1, and the 
remaining n objects having grade 0. The second list has the objects in the reverse order, again with 
the top n + 1 objects having grade 1, and the remaining n objects having grade 0. As before, there 
is a unique object with overall grade 1 (namely, the object in the middle of both orderings), and every 
remaining object has overall grade 0. 

Let A be an arbitrary deterministic algorithm in A. Consider the following distribution on databases: 
each member is as above, and the ordering of the first list is chosen uniformly at random (with the 
ordering of the second list the reverse of the ordering of the first list). It is easy to see that the expected 
number of accesses (sorted and random together) of algorithm A under this distribution in order to even 
see the winning object is at least n + 1. Since there must be some database where the number of accesses 
is at least equal to the expected number of accesses, the number of accesses on this database is at least 
n + 1. However, as in Example |63| , there is an algorithm that makes only 2 random accesses and no 
sorted accesses. Therefore, the optimahty ratio can be arbitrarily large. The theorem follows (in the 
deterministic case). 

For probabilistic algorithms that never make a mistake, we appeal to Yao's Minimax Principle [?] 
(see also [?, Section 2.2], and see [?, Lemma 4] for a simple proof), which says that the expected cost of 
the optimal deterministic algorithm for an arbitrary input distribution is a lower bound on the expected 
cost of the optimal probabilistic algorithm that never makes a mistake. □ 

Although, as we noted earlier, algorithms that make wild guesses would not normally be imple- 
mented in practice, it is still interesting to consider them. This is because of our interpretation of 
instance optimality of an algorithm A as saying that its cost is essentially the same as the cost of the 
shortest proof for that database that these are really the top k answers. If we consider algorithms that 

"The algorithm could halt safely, since it "knows" that it has found an object with the maximal possible grade of 1 (this 
grade is maximal, since we are assuming that all grades lie between and 1). Even if we did not assume that all grades lie 
between and 1, one sorted access to either list would provide the information that each overall grade in the database is at 
most 1. 
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allow wild guesses, then we are allowing a larger class of proofs. Thus, in Example |63| , the fact that 
object n + 1 has (overall) grade 1 is a proof that it is the top answer. 

We say that an aggregation function t is strictly monoton^^ if t{xi, . . . , Xm) < t{x'i, . . . , x'^) 
whenever Xi < x\ for every i. Although average and min are strictly monotone, there are aggregation 
functions suggested in the hterature for representing conjunction and disjunction that are monotone but 
not strictly monotone (see [?] and [?] for examples). We say that a database T> satisfies the distinctness 
property if for each i, no two objects in V have the same grade in list Lj, that is, if the grades in list Lj 
are distinct. We now show that these conditions guarantee optimality of TA even among algorithms that 
make wild guesses. 

Theorem 6.5: Assume that the aggregation function t is strictly monotone. Let D be the class of all 
databases that satisfy the distinctness property. Let A be the class of all algorithms that correctly find 
the top k answers for tfor every database in D. Then TA is instance optimal over A and D. 

Proof: Assume that ^ e A, and that algorithm A is run over database D e D. Assume that A sees 
a distinct objects (some possibly multiple times). We shall show that TA halts on V by depth a + k. 
Hence, TA makes at most m?'{a+k) accesses, which is rn^a plus an additive constant of m?k. It follows 
easily that the optimality ratio of TA is at most cm?, where c = max {cr/cs, cs / cr\. 

If there are at most k objects that A does not see, then TA halts by depth a + k (after having seen 
every object), and we are done. So assume that there are at least k + 1 objects that A does not see. Since 

Y is of size k, there is some object V that A does not see and that is not in Y . We shall show that TA 
halts on V by depth a + 1. 

Let r be the threshold value of TA at depth a + 1. Thus, if Xj is the grade of the (a + l)th highest 
object in list i, then r = t{xi, . . . ,x^). Let us call an object R big if t{R) > r, and otherwise call 
object R small. (Note that these definitions of "big" and "small" are different from those in the proof of 
Theorem |6.1| .) 

We now show that every member i? of y is big. Let x • be some grade in the top a + 1 grades in list 
i that is not the grade in list i of any object seen by A. There is such a grade, since all grades in list i 
are distinct, and A sees at most a objects. Let V agree with V on all objects seen by A, and let object 

V have grade x[ in the ith list of V, for 1 < i < m. Hence, the grade of V in V is t{x'i, . . . , x'^) > r. 
Since V was unseen, and since V is assigned grades in each list in V below the level that A reached by 
sorted access, it follows that algorithm A performs exactly the same, and in particular gives the same 
output, for databases V and V. Therefore, algorithm A has R, but not V, in its output for database V. 
By correctness of A, it follows that R is big, as desired. 

We claim that every member i? of y is one of the top a + I members of some list i (and so is seen 
by TA by depth a + 1). Assume by way of contradiction that R is not one of the top a + 1 members 
of list i, for 1 < i < m. By our assumptions that the aggregation function t is strictly monotone, and 
that V satisfies the distinctness property, it follows easily that R is small. We already showed that every 
member of Y is big. This contradiction proves the claim. It follows that TA halts by depth a + 1, as 
desired. □ 



In the proof of Theorem p.5| , we showed that under the assumptions of Theorem |6^ (strict mono- 
tonicity and the distinctness property) the optimality ratio of TA is at most cm? , where c = max {cr/cs, cs / 

'"This should not be confused with the aggregation function being both strict and monotone. We apologize for the clash in 
terminology, which exists for historical reasons. 
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In Theorem 92 , we give an aggregation function that is strictly monotone such that no deterministic al- 
gorithm can have an optimality ratio of less than ^^^fj- So in our case of greatest interest, where 
cr > cs, there is a gap of around a factor of 2m in the upper and lower bounds. 



The proofs of Theorems 6.1 and 6.5 have several nice properties: 



The proofs would still go through if we were in a scenario where, whenever a random access of 
object R in list i takes place, we learn not only the grade of R in list i, but also the relative rank. 
Thus, TA is instance optimal even when we allow A to include also algorithms that learn and 
make use of such relative rank information. 

As we shall see, we can prove the instance optimality among approximation algorithms of an 



approximation version of TA, under the assumptions of Theorem 5.1, with only a small change to 



the proof (as we shall see, such a theorem does not hold under the assumptions of Theorem 
6.1 Treating k and m as Constants 



In Theorems |6J and |6^ about the instance optimality of TA, we are treating k (where we are trying 
to find the top k answers) and m (the number of sorted lists) as constants. We now discuss these 
assumptions. 



We begin first with the assumption that k is constant. As in the proofs of Theorems |6JJ and | 
let a be the number of accesses by an algorithm ^ G A. If a > fc, then there is no need to treat k as 
a constant. Thus, if we were to restrict the class A of algorithms to contain only algorithms that make 
at least k accesses to find the top k answers, then there would be no need to assume that k is constant. 
How can it arise that an algorithm A can find the top k answers without making at least k accesses, 
and in particular without accessing at least k objects? It must then happen that either there are at most 
k objects in the database, or else every object R that A has not seen has the same overall grade t{R). 
The latter will occur, for example, if t is a constant function. Even under these circumstances, it is still 
not reasonable in some contexts (such as certain database contexts) to allow an algorithm A to output 
an object as a member of the top k objects without ever having seen it: how would the algorithm even 
know the name of the object? This is similar to an issue we raised earlier about wild guesses. 

What about the assumption that m is constant? As we noted earlier, this is certainly a reasonable 
assumption, since m is the number of arguments of the aggregation function, which we are of course 



taking to be fixed. In the case of the assumptions of Theorem 6.1 (no wild guesses). Corollary 6.2 tells 



us that at least for strict aggregation functions, this dependence on m is inevitable. Similarly, in the case 



of the assumptions of Theorem 5.5 (strict monotonicity and the distinctness property). Theorem |9.2| tells 



us that at least for certain aggregation functions, this dependence on m is inevitable. 



6.2 Turning TA into an Approximation Algorithm, and Allowing Early Stopping 

TA can easily be modified to be an approximation algorithm. It can then be used in situations where we 
care only about the approximately top k answers. Thus, let > 1 be given. Define a 6 -approximation 
to the top k answers (for t over database Dj to be a collection of k objects (and their grades) such that 
for each y among these k objects and each z not among these k objects, Ot{y) > t{z). We can modify 
TA to find a 6'-approximation to the top k answers by modifying the stopping rule in Step 2 to say "As 
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Figure 2: Database for Example 



soon as at least k objects have been seen whose grade is at least equal to t/9, then halt." Let us call this 
approximation algorithm TAg. 

Theorem 6.6: Assume that 9 > 1 and that the aggregation function t is monotone. Then TAg correctly 
finds a 6 -approximation to the top k answers for t. 



Proof: This follows from a straightforward modification of the proof of Theorem |4. 1| . □ 



The next theorem says that when we restrict attention to algorithms that do not make wild guesses, 
then TAg is instance optimal. 



Theorem 6.7: Assume that 6 > 1 and that the aggregation function t is monotone. Let D be the class of 
all databases. Let A be the class of all algorithms that find a 9-approximation to the top k answers for 
tfor every database and that do not make wild guesses. Then TAg is instance optimal over A and D. 



Proof: The proof of Theorem carries over verbatim provided we modify the definition of an object 
R being "big" to be that 9t{R) > r^. □ 



Theorem 6.7 shows that the analog of Theorem 6.1 holds for TAg. The next example, which is 
a modification of Example |6.3i shows that the analog of Theorem does not hold for TAg. One 
interpretation of these results is that Theorem |6.1| is sufficiently robust that it can survive the perturbation 
of allowing approximations, whereas Theorem |6.5| is not. 



Example 6.8: Assume that 9 > 1, that there are 2n + 1 objects, which we will call simply 1, 2, . . . , 2n + 
1, and that there are two lists Li and L2 (see Figure ^.f^ Assume that in list Li, the grades are assigned 
so that all grades are different, the ordering of the objects by grade is 1, 2, . . . , 2n + 1, object n + 1 has 
the grade 1/9, and object n + 2 has the grade 1/(20^). Assume that in list L2, the grades are assigned 
so that all grades are different, the ordering of the objects by grade is 2n + 1, 2n, . . . , 1 (the reverse of 
the ordering in Li), object n + 1 has the grade 1/9, and object n has the grade 1 / {29"^). Assume that the 
aggregation function is min, and that = 1 (so that we are interested in finding a ^-approximation to the 
top answer). The (overall) grade of each object other than object n + 1 is at most a = 1/(29"^). Since 
9a = l/{29), which is less than the grade 1/9 of object n + 1, it follows that the unique object that can 

"in this and later figures, each centered dot represents a value that it is not important to give explicitly. 
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be returned by an algorithm such as TAg that correctly finds a 6'-approximation to the top answer is the 
object n + 1. 

An algorithm that makes a wild guess and asks for the grade of object n + 1 in both lists would 
determine the correct answer and be able to halt safely after two random accesses and no sorted accesses. 
The algorithm could halt safely, since it "knows" that it has found an object R such that 9t{R) = 1, 
and so 6t{R) is at least as big as every possible grade. However, under sorted access for list Li, the 
algorithm TAg would see the objects in the order 1, 2, . . . , 2n + 1, and under sorted access for list L2, 
the algorithm TAg would see the objects in the reverse order. Since the winning object n + 1 is in the 
middle of both sorted hsts, it follows that at least n + I sorted accesses would be required before TAg 
would even see the winning object. □ 



Just as we converted Example |63| into Theorem |6^, we can convert Example |6^ into the following 
theorem. 

Theorem 6.9: Assume that 9 > 1. Let D be the class of all databases that satisfy the distinctness 
property. Let A be the class of all algorithms that find a 9 -approximation to the top answer for minfor 
every database in D. There is no deterministic algorithm (or even probabilistic algorithm that never 
makes a mistake) that is instance optimal over A and D. 

Early stopping of TA: It is straightforward to modify TAg into an interactive process where at all 
times the system can show the user the current top k list along with a guarantee about the degree of 
approximation to the correct answer. At any time, the user can decide, based on this guarantee, whether 
he would like to stop the process. Thus, let (i be the grade of the fcth (bottom) object in the current top 
k list, let T be the cun^ent threshold value, and let 6* = t//3. If the algorithm is stopped early, we have 
9 > 1. It is easy to see that similarly to the situation of Theorem |6.6[ , the current top k list is then a 
^-approximation to the top k answers. Thus, the user can be shown the current top k list and the number 
9, with a guarantee that he is being shown a ^-approximation to the top k answers. 



7 Restricting Sorted Access 

Bruno, Gravano, and Marian [?] discuss a scenario where it is not possible to access certain of the lists 
under sorted access. They give a nice example where the user wants to get information about restaurants. 
The user has an aggregation function that gives a score to each restaurant based on how good it is, how 
inexpensive it is, and how close it is. In this example, the Zagat-Review web site gives ratings of 
restaurants, the NYT-Review web site gives prices, and the MapQuest web site gives distances. Only 
the Zagat-Review web site can be accessed under sorted access (with the best restaurants at the top of 
the Ust). 

Let Z be the set of indices i of those lists Li that can be accessed under sorted access. We assume 
that Z is nonempty, that is, that at least one of the lists can be accessed under sorted access. We take m' 
to be the cardinality \Z\of Z (and as before, take m to be the total number of sorted lists). Define TA^ 
to be the following natural modification of TA, that deals with the restriction on sorted access. 

1. Do sorted access in parallel to each of the m' sorted lists Li with z € Z. As an object R is seen 
under sorted access in some list, do random access as needed to the other hsts to find the grade Xi 
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of object R in every list Lj. Then compute the grade t{R) = . . . , Xm) of object R. If this 
grade is one of the k highest we have seen, then remember object R and its grade t{R) (ties are 
broken arbitrarily, so that only k objects and their grades need to be remembered at any time). 

2. For each list Li with i G Z, let Xj be the grade of the last object seen under sorted access. For 
each list Li with i ^ Z, let Xj = 1. Define the threshold value r to be t{xi, . . . ,x^). As soon as 
at least k objects have been seen whose grade is at least equal to r, then halt.[^ 

3. Let y be a set containing the k objects that have been seen with the highest grades. The output is 
then the graded set {{R, t{R)) \R£Y}. 



In the case where \Z\ = 1, algorithm TAz is essentially the same as the algorithm TA- Adapt in [?]. 

In footnote 5, we noted that each of the algorithms in this paper where there is "sorted access in 
parallel" remain correct even when sorted access is not in lockstep. Algorithm TA^ provides an extreme 
example, where only some of the sorted lists are accessed under sorted access, and the remaining sorted 
lists are accessed under random access only. 

We now show that Theorem |6.1[ , which says that TA is instance optimal when we restrict attention to 
algorithms that do not make wild guesses, and Corollary |6.2| , which says that the optimality ratio of TA 
is best possible when we restrict attention to algorithms that do not make wild guesses, both generalize 
to hold for TA^. What about our other theorem about instance optimality of TA (Theorem 6.5), which 
says that TA is instance optimal when the aggregation function t is strictly monotone and the class of 
legal databases satisfies the distinctness property? Interestingly enough, we shall show (Example 7.3) 
that this latter theorem does not generalize to TA^. 



Theorem 7.1: Assume that the aggregation function t is monotone. Let D be the class of all databases. 
Let A be the class of all algorithms that correctly find the top k answers for t for every database and 
that do not make wild guesses, where the only lists that may be accessed under sorted access are those 
lists Li with i ^ Z. Then TAz is instance optimal over A and D. 



Proof: The proof is essentially the same as the proof of Theorem |6j, except for the bookkeeping. 
Assume that A G A, and that algorithm A is run over database V. Assume that algorithm A halts at 
depth d (that is, if di is the number of objects seen under sorted access to list i, for 1 < i < m, then 
d = maxj di). Assume that A sees a distinct objects (some possibly multiple times). Since A makes no 
wild guesses, and sees o distinct objects, it must make at least a sorted accesses, and so its middleware 
cost is at least acs. By the same proof as that of Theorem it follows that TA^ halts on V by depth 
a + k. Hence, the middleware cost of TA^ is at most (a + k)m'cs + (a + k)m'{m — 1)cr, which is 
am'cs + am'{m — \)cr plus an additive constant of km'cs + km'{m — 1)cr. So the optimality ratio 

of TA^ is at most ""^ cs+am{m-l)cji _ ^/ _|_ ^'^^ _ I'jcji/cs. □ 



The next result, which is analogous to Corollary |6.2| , is a corollary of the proof of Theorem [7J| and 
of a lower bound in Section ^ 

"*As we shall see in Example [7.3[ even though there are at least k objects, it is possible that after seeing the grade of every 
object in every list, and thus having done sorted access to every object in every list Li with i £ Z, there are not at least k 
objects with a grade that is at least equal to the final threshold value r. In this situation, we say that TAz halts after it has seen 
the grade of every object in every list. This situation cannot happen with TA. 
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Figure 3: Database for Example 7.3 



Corollary 7.2: Let t be an arbitrary monotone, strict aggregation function with m arguments. Assume 
that \Z\ = m'. Let D be the class of all databases. Let A be the class of all algorithms that correctly 
find the top k answers for tfor every database, and that do not make wild guesses, where the only lists 
that may be accessed under sorted access are those lists Li with i ^ Z. Then TAz is instance optimal 
over A and D, with optimality ratio m' + m'{m — l)cji/cs. No deterministic algorithm has a lower 
optimality ratio. 

Proof: In the proof of Theorem [7.1| , it is shown that TAz has an optimality ratio of at most m' + 
m'{m — \-)cr/cs for an arbitrary monotone aggregation function, The lower bound follows from a 
minor variation of the proof of Theorem |9. 1| , where we take if) = {dm' — \)cs -\- {dm' — \){m — \)cr. 
The simple details are left to the reader. □ 



Theorem |6^ says that if the aggregation function t is strictly monotone, and if the class of legal 
databases satisfies the distinctness property, then TA is instance optimal. We now show by example that 
the analogous result fails for TA^. In fact, we shall show that TA^ need not be instance optimal even if 
we assume not only that aggregation function t is strictly monotone, and that the class of legal databases 
satisfies the distinctness property, but in addition we assume that the aggregation function t is strict, and 
that no wild guesses are allowed. 



Example 7.3: Assume that the database satisfies the distinctness property, that there are only three sorted 
lists Li, L2, and L3 (see Figure ^, and that Z = {1} (so that only Li may be accessed under sorted 
access). Let t be the aggregation function where t{x,y,z) = min{x,y} if z = 1, and t{x,y,z) = 
(min {x, y, z})/2 if z ^ I. It is easy to see that t is strictly monotone and strict. Assume that we are 
interested in finding the top answer (i.e., k = 1). 

Assume that object R has grade 1 in lists Li and L3, and grade 0.6 in list L2. Hence t{R) = 0.6. 
Note that for each object R' other than R, necessarily the grade of R' in L3 is not 1 (by the distinctness 
property), and so t{R') < 0.5. Therefore, R is the unique top object. 

Assume that the minimum grade in list Li is 0.7. It follows that the threshold value is never less 
than 0.7. Therefore, TA^ does not halt until it has seen the grade of every object in every list. However, 
let A be an algorithm that does sorted access to the top object R in list Li and random access to R in 
lists L2 and L3, and then halts and announces that R is the top object. Algorithm A does only one sorted 
access and two random accesses on this database. It is safe for algorithm A to halt, since it "knows" 
that object R has grade 0.6 and that no other object can have grade bigger than 0.5. Since there can be 
an arbitrarily large number of objects, it follows that TA^ is not instance optimal. Hence, the analogue 
of Theorem ^ fails for TA^. 

It is instructive to understand "what goes wrong" in this example and why this same problem does 



not also cause Theorems |6^ or [7J| to fail. Intuitively, what goes wrong in this example is that the 
threshold value is too conservative an estimate as an upper bound on the grade of unseen objects. By 
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contrast, in the case of Theorem [7.1[ some unseen object may have an overall grade equal to the threshold 
value, so the threshold value is not too conservative an estimate. In the case of Theorem |6.5i an analysis 
of the proof shows that we consider the threshold value at depth a + 1 rather than depth a. Intuitively, 
although the threshold value may be too conservative an estimate, the threshold value one extra level 
down is not. □ 

8 Minimizing Random Access 

Thus far in this paper, we have not been especially concerned about the number of random accesses. 
For every sorted access in TA, up to m — 1 random accesses take place. Recall that if s is the number 
of sorted accesses, and r is the number of random accesses, then the middleware cost is scs + rcn, for 
some positive constants cs and cr. Our notion of instance optimality ignores constant factors like m and 
cr (they are simply multiplicative factors in the optimality ratio). Hence, there has been no motivation 
so far to concern ourself with the number of random accesses. 

There are, however, some scenarios where we must pay attention to the number of random accesses. 
The first scenario is where random accesses are impossible (which corresponds to c/j = oo). As we 
discussed in Section ^, an example of this first scenario arises when the middleware system is a text 
retrieval system, and the sorted lists correspond to the results of search engines. Another scenario is 
where random accesses are not impossible, but simply expensive relative to sorted access. An example 
of this second scenario arises when the costs correspond to disk access (sequential versus random). Then 
we would like the optimality ratio to be independent of cr/cs- That is, if we allow cr and cs to vary, 
instead of treating them as constants, we would still like the optimality ratio to be bounded. 

In this section we describe algorithms that do not use random access frivolously. We give two 
algorithms. One uses no random accesses at all, and hence is called NRA ("No Random Access"). The 
second algorithm takes into account the cost of a random access. It is a combination of NRA and TA, 
and so we call it CA ("Combined Algorithm"). 

Both algorithms access the information in a natural way, and, in the spirit of the knowledge-based 
programs of Section Q halt when they know that no improvement can take place. In general, at each 
point in an execution of these algorithms where a number of sorted and random accesses have taken 
place, for each object R there is a subset S{R) = {ii,i2, ■ ■ ■ , it} C {!,..., m} of the fields of R 
where the algorithm has determined the values , , • • • , Xi^, of these fields. Given this information, 
we define functions of this information that are lower and upper bounds on the value t{R) can obtain. 
The algorithm proceeds until there are no more candidates whose current upper bound is better than the 
current A;th largest lower bound. 

Lower Bound: Given an object R and subset S{R) = {ii,i2, ■ ■ ■ ,ie} Q {!,..., m} of known 
fields of R, with values , , . . . , Xi^ for these known fields, we define Ws{R) (or W(R) if the subset 
S = S{R) is understood from the context) as the minimum (or worst) value the aggregation function t 
can attain for object R. When t is monotone, this minimum value is obtained by substituting for each 
missing field i E {1, . . . , m}\S the value 0, and applying t to the result. For example, if S = {1, . . . , f\, 
then Ws{R) = t{xi,X2, . . . , x^, 0, . . . , 0). The following property is immediate from the definition: 

Proposition 8.1: If S is the set of known fields of object R, then t{R) > Ws{R)- 

In other words, W{R) represents a lower bound on t{R). Is it the best possible? Yes, unless we have 
additional information, such as that the value does not appear in the lists. In general, as an algorithm 
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progresses and we learn more fields of an object R, its W value becomes larger (or at least not smaller). 
For some aggregation functions t the value W{R) yields no knowledge until S includes all fields: for 
instance if t is min, then W{R) is until all values are discovered. For other functions it is more 
meaningful. For instance, when t is the median of three fields, then as soon as two of them are known 
W{R) is at least the smaller of the two. 

Upper Bound: The best value an object can attain depends on other information we have. We will 
use only the bottom values in each field, defined as in TA: Xj is the last (smallest) value obtained via 
sorted access in list Li. Given an object R and subset S{R) = {ii,i2, ■ ■ ■ , ie} C {1, . . . , m} of known 
fields of R, with values Xi^^^Xi^, . . . , Xi^ for these known fields, we define Bs{R) (or B(R) if the subset 
S is understood from the context) as the maximum (or best) value the aggregation function t can attain 
for object R. When t is monotone, this maximum value is obtained by substituting for each missing 
field i E {1, . . . , m}\S the value Xj, and applying t to the result. For example, if S = {1, . . . ,£}, then 
Bs{R) = t{xi,X2, . . . , xe,Xl_^_l, . . . , x^). The following property is immediate from the definition: 

Proposition 8.2: If S is the set of known fields of object R, then t{R) < Bs{R)- 

In other words, B{R) represents an upper bound on the value t{R) (or the best value t{R) can 
be), given the information we have so far. Is it the best upper bound? If the lists may each contain 
equal values (which in general we assume they can), then given the information we have it is possible 
that t{R) = Bs{R)- If the distinctness property holds (equalities are not allowed in a list), then for 
continuous aggregation functions t it is the case that B{R) is the best upper bound on the value t can 
have on R. In general, as an algorithm progresses and we learn more fields of an object R and the 
bottom values Xj decrease, B{R) can only decrease (or remain the same). 

An important special case is an object R that has not been encountered at all. In this case B{R) = 
t{xi,X2, . . . , x^). Note that this is the same as the threshold value in TA. 

8.1 No Random Access Algorithm — NRA 

As we have discussed, there are situations where random accesses are impossible. We now consider 
algorithms that make no random accesses. Since random accesses are impossible, in this section we 
change our criterion for the desired output. In earlier sections, we demanded that the output be the "top 
k answers", which consists of the top k objects, along with their (overall) grades. In this section, we 
make the weaker requirement that the output consist of the top k objects, without their grades. The 
reason is that, since random access is impossible, it may be much cheaper (that is, require many fewer 
accesses) to find the top k objects without their grades. This is because, as we now show by example, 
we can sometimes obtain enough partial information about grades to know that an object is in the top k 
objects without knowing its exact grade. 

Example 8.3: Consider the following scenario, where the aggregation function is the average, and where 
k = I (so that we are interested only in the top object). There are only two sorted lists Li and L2 (see 
Figure ^), and the grade of every object in both Li and L2 is 1/3, except that object R has grade 1 in 
Li and grade in L2. After two sorted accesses to Li and one sorted access to L2, there is enough 
information to know that object R is the top object (its average grade is at least 1/2, and every other 
object has average grade at most 1/3). If we wished to find the grade of object R, we would need to do 
sorted access to all of L2. □ 
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Figure 4: Database for Example 



Note that we are requiring only that the output consist of the top k objects, with no information being 
given about the sorted order (sorted by grade). If we wish to know the sorted order, this can easily 
be determined by finding the top object, the top 2 objects, etc. Let Cj be the cost of finding the top i 
objects. It is interesting to note that there is no necessary relationship between Cj and Cj for i < j. For 



example, in Example 8.3, we have Ci < C2. If we were to modify Example 8.3 so that there are two 
objects R and R' with grade 1 in Li, where the grade of R in L2 is 0, and the grade of R' in L2 is 1/4 
(and so that, as before, all remaining grades of all objects in both lists is 1/3), then C2 < Ci. 

The cost of finding the top k objects in sorted order is at most k maxj Cj. Since we are treating k 
as a constant, it follows easily that we can convert our instance optimal algorithm (which we shall give 
shortly) for finding the top k objects into an instance optimal algorithm for finding the top k objects in 
sorted order. In practice, it is usually good enough to know the top k objects in sorted order, without 
knowing the grades. In fact, the major search engines on the web no longer give grades (possibly to 
prevent reverse engineering). 

The algorithm NRA is as follows. 



1. Do sorted access in parallel to each of the m sorted lists Li. At each depth d (when d objects have 
been accessed under sorted access in each list): 

• Maintain the bottom values x^^ , ^2*^^ , • • • , Xm^ encountered in the lists. 

• For every object R with discovered fields S = S^'^\R) C {!,..., m}, compute the values 

= WsiR) and B^'^\R) = BsiR). (For objects R that have not been seen, these 
values are virtually computed as W^^\R) = t{0, . . . , 0), and B^^\R) = t{xi,X2, ■ ■ ■ , x^), 
which is the threshold value.) 

• Let Tlf'\ the current top k list, contain the k objects with the largest T^('^) values seen so 
far (and their grades); if two objects have the same W^"^^ value, then ties are broken using 
the B^'^^ values, such that the object with the highest B^*^^ value wins (and arbitrarily among 
objects that tie for the highest B^'^^ value). Let ujf^ be the kth largest W^'^^ value in Tjf\ 

2. Call an object R viable if B'^^^R) > Mjf\ Halt when (a) at least k distinct objects have been 
seen (so that in particular Tjf^ contains k objects) and (b) there are no viable objects left outside 
Tlf\ that is, when B'^'^'>{R) < Mf^ for all R ^ TjfK Return the objects in Tjf\ 

We now show that NRA is correct for each monotone aggregation function t. 



Theorem 8.4: If the aggregation function t is monotone, then NRA correctly finds the top k objects. 
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Proof: Assume that NRA halts after d sorted accesses to each Ust, and that xjf^ = {Ri,R2, . . . , Rk}- 
Thus, the objects output by NRA are Ri, R2, . . . , Rk- Let R be an object not among Ri, R2, ■ ■ ■ , Rk- 
We must show that t{R) < t{Ri) for each i. 

Since the algorithm halts at depth d, we know that R is nonviable at depth d, that is, B^'^^R) < 
Mjf\ Now t{R) < (Proposition Also for each of the k objects Ri we have Adjf'^ < 



W^'^\Ri) < t{Ri) (from Proposition 8.1 and the definition of Mjf^). Combining the inequalities we 
have shown, we have 

t{R) < B^'^\r) < M'f^ < W^'^\Ri) < t{Ri 

for each i, as desired. □ 



'^k 

r(d) 



Note that the tie-breaking mechanism was not needed for correctness (but will be used for instance 
optimality). We now show instance optimality of NRA over all algorithms that do not use random 
access: 

Theorem 8.5: Assume that the aggregation function t is monotone. Let D be the class of all databases. 
Let A be the class of all algorithms that correctly find the top k objects for tfor every database and that 
do not make random accesses. Then NRA is instance optimal over A and D. 

Proof: Assume A G A. If algorithm NRA halts at depth d, and NRA saw at least k distinct objects for 
the first time by depth d, then NRA makes only a constant number of accesses (at most km"^) on that 
database. So suppose that on some database V, algorithm NRA halts at depth d, and that NRA saw at 
least k distinct objects by depth d — 1. We claim that A must get to depth d in at least one of the lists. It 
then follows that the optimahty ratio of NRA is at most m, and the theorem follows. Suppose the claim 
fails; then from the fact that algorithm NRA did not halt at depth d — 1 there is an object R ^ T^f" 
such that B('^-^\R) > Mjf~'^\ We know that W^'^-^'^{R) < m[^'^\ since R ^ Tjf~'^^ Further, we 
know from the tie-breaking mechanism that if W'^'^^^^R) = Aljf ^\ then for each Ri G T^'^ such 
that VF('^)(i?i) = Mjf^ necessarily B^'^-^\Ri) > B'^'^-'^\R). 

There are now two cases, depending on whether or not algorithm A outputs R as one of the top k 
objects. In either case, we construct a database on which A errs. 

Case 1: Algorithm A outputs R as one of the top k objects. We construct a database V where 
A errs as follows. Database V is identical to V up to depth d — 1 (that is, for each i the top d — 1 
objects and their grades are the same in list Li for V as for V). For each Ri and for each missing field 

assign value x^^ For the object R assign all of the missing fields in 
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{!,..., m}\S^'^^'^^ (R) the value 0. We now show that t{R) < t{Rj) for each j with l<j<k. Hence, 
R is not one of the top k objects, and so algorithm A erred. First, we have 

t{R) = W^'^'^\R) < Mjf~^^ (3) 
Also, for all i with 1 < i < k we have 

^id-i) < < B^''-^\r,) = t{Ri). (4) 

If < mI^'^\ then we have from (|) and (|) that t[R) < t{Ri) for each i, as desired. 

So assume that W^'^^^^iR) = ujf ^\ A gain, we wish to show that t{R) < t{Ri) for each i. We 
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consider separately in two subcases those i where Mjf" = W'^'^ and those where Mjf ^ 

Subcase 1: = W^'^-'^\Ri). Then t{R) < Mjf~^'^ < B^'^-^\R) < B^'^'^\Ri) = t{Ri), 

as desired, where the last inequality follows from the tie-breaking mechanism. 

Subcase 2: Mjf'^^ / W^'^^^^Ri), and so Mjf^'^^ < W^'^'^^Ri). From the inequalities in @, 
we see that Mjf'^^ < t{Ri). So by we have t{R) < t{Ri), as desired. 

Case 2: Algorithm A does not output R as one of the top k objects. We construct a database 
V" where A errs as follows. Database V" is identical to V up to depth d — I. At depth d it gives 
each missing field i € {1, . . . , m}\S^'^^^^ (R) of R the value xf'' ^\ For all remaining missing fields, 
including missing fields of Ri, . . . , Rk, assign the value 0. Now t{R) = i?^'^^^) (i?) > Mjf , whereas 
(a) for at least one Ri (namely, that Ri where W'-'^\Ri) = M^'^^) we have t{Ri) = Mf~^\ and (b) 

for each object R' not among Ri, R2, ■ ■ ■ , Rk or R we have that t{R') < Adjf ^\ Hence, algorithm A 
erred in not outputting R as one of the top k objects. □ 

Note that the issue of "wild guesses" is not relevant here, since we are restricting our attention to 
algorithms that make no random accesses (and hence no wild guesses). 

The next result, which is analogous to Corollaries |6!^ and is a corollary of the proof of Theo- 
rem 8^ and of a lower bound in Section ^. Specifically, in the proof of Theorem 8^ , we showed that 
the optimality ratio of NRA is at most m. The next result says that if the aggregation function is strict, 
then the optimality ratio is precisely m, and this is best possible. 

Corollary 8.6: Let t be an arbitrary monotone, strict aggregation function with m arguments. Let D be 
the class of all databases. Let A be the class of all algorithms that correctly find the top k objects for 
tfor every database and that do not make random accesses. Then NRA is instance optimal over A and 
D, with optimality ratio m. No deterministic algorithm has a lower optimality ratio. 



Proof: In the proof of Theorem p.% it is shown that NRA has an optimality ratio of at most m for an 



arbitrary monotone aggregation function. The lower bound follows from Theorem 5.5. □ 



Remark 8.7: Unfortunately, the execution of NRA may require a lot of bookkeeping at each step, since 
when NRA does sorted access at depth I (for 1 < I < d), the value of B^^'^ (R) must be updated for every 
object R seen so far. This may be up to £m updates for each depth i, which yields a total of Q{d'^m) 
updates by depth d. Furthermore, unlike TA, it no longer suffices to have bounded buffers. However, 
for a specific function like min it is possible that by using appropriate data structures the computation 
can be greatly simplified. This is an issue for further investigation. □ 

8.2 Taking into Account the Random Access Cost 

We now present the combined algorithm CA that does use random accesses, but takes their cost (relative 
to sorted access) into account. As before, let cs be the cost of a sorted access and cr be the cost of a 
random access. The middleware cost of an algorithm that makes s sorted accesses and r random ones 
is scs + rcR. We know that TA is instance optimal; however, the optimality ratio is a function of the 
relative cost of a random access to a sorted access, that is cr/cs. Our goal in this section is to find an 
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algorithm that is instance optimal and where the optimality ratio is independent of cr/cs- One can view 
CA as a merge between TA and NRA. Let h = \cr/cs\- We assume in this section that cr > cs, so 
that h > 1. The idea of CA is to run NRA, but every h steps to run a random access phase and update 
the information (the upper and lower bounds B and W) accordingly. As in Section |8.1[ , in this section 
we require only that the output consist of the top k objects, without their grades. If we wish to obtain 
the grades, this requires only a constant number of additional random accesses, and so has no effect on 
instance optimality. 

The algorithm CA is as follows. 

1. Do sorted access in parallel to each of the m sorted lists Lj. At each depth d (when d objects have 
been accessed under sorted access in each list): 

• Maintain the bottom values x^^^ , ^2*^^ , • • • , sM^ encountered in the lists. 

• For every object R with discovered fields S = S^'^\R) C {1, . . . , m}, compute the values 
W^'^^R) = Ws{R) and B^'^\R) = Bs{R). (For objects R that have not been seen, these 
values are virtually computed as W^'^\R) = t(0, . . . , 0), and B^'^^R) = t{xi,X2, . . . , x^), 
which is the threshold value.) 

• Let T^'^\ the current top k list, contain the k objects with the largest W^'^^ values seen so 
far (and their grades); if two objects have the same W^'^^ value, then ties are broken using 
the B^'^^ values, such that the object with the highest B^'^^ value wins (and arbitrarily among 
objects that tie for the highest S^"^) value). Let M^''^ be the kth largest W^'^'^ value in T^'^K 

2. Call an object R viable if B'^'^\R) > Every h = \cr/cs\ steps (that is, every time the 
depth of sorted access increases by h), do the following: pick the viable object that has been seen 
for which not all fields are known and whose B^'^^ value is as big as possible (ties are broken 
arbitrarily). Perform random accesses for all of its (at most m — 1) missing fields. If there is no 
such object, then do not do a random access on this step[^ 

3. Halt when (a) at least k distinct objects have been seen (so that in particular contains k 
objects) and (b) there are no viable objects left outside T^f* , that is, when B^'^^R) < ujf^ for 
all R Tjf \ Return the objects in T^'^^ 

Note that if h is very large (say larger than the number of objects in the database), then algorithm 
CA is the same as NRA, since no random access is performed. If h = 1, then algorithm CA is similar 
to TA, but different in intriguing ways. For each step of doing sorted access in parallel, CA performs 
random accesses for all of the missing fields of some object. Instead of performing random accesses for 
all of the missing fields of some object, TA performs random accesses for all of the missing fields of 



every object seen in sorted access. Later (Section 8.4), we discuss further CA versus TA. 



For moderate values of h it is not the case that CA is equivalent to the intermittent algorithm that 
executes h steps of NRA and then one step of TA. (That is, the intermittent algorithm does random 

The reason for this escape clause is so that CA does not make a wild guess. We now give an example where this escape 
clause may be invoked. Assume that k = 2 and cr = cs- Assume that on the first round of sorted access in parallel, the same 
object appears in all of the lists. Then on the first opportunity to do a random access, the escape clause must be invoked, since 



every field is known for the only object that has been seen. In the proof of Theorem ^.9, we show that if the escape clause is 
invoked after depth k (that is, after there has been at least k rounds of sorted access in parallel), then CA halts immediately 
after. 
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accesses in the same time order as TA does, but simply delays them, so that it does random accesses 



every h steps.) We show later (Section |8.4| ) an example where the intermittent algorithm performs much 
worse than CA. The difference between the algorithms is that CA picks "wisely" on which objects to 
perform the random access, namely, according to their B^'^^ values. Thus, it is not enough to consider 
the knowledge-based program of Section ^ to design the instance optimal algorithm CA; we need also 
a principle as to which objects to perform the random access on. This was not an issue in designing TA, 
since in that context, random accesses increase the cost by only a constant multiple. 

CoiTcctness of CA is essentially the same as for NRA, since the same upper and lower bounds are 
maintained: 

Theorem 8.8: If the aggregation function t is monotone, then CA correctly finds the top k objects. 

In the next section, we consider scenarios under which CA is instance optimal, with the optimality 
ratio independent of cr/cs- 



8.3 Instance Optimality of CA 

In Section ^ we gave two scenarios under which TA is instance optimal over A and D. In the first sce- 



nario (from Theorem p. 1[ ), (1) the aggregation function t is monotone; (2) D is the class of all databases; 
and (c) A is the class of all algorithms that correctly find the top k objects for t for every database and 
that do not make wild guesses. In the second scenario (from Theorem |6^ ), (1) the aggregation function 
t is strictly monotone; (2) D is the class of all databases that satisfy the distinctness property; and (3) A 
is the class of all algorithms that correctly find the top k objects for t for every database in D. We might 
hope that under either of these two scenarios, CA is instance optimal, with optimality ratio independent 
of cr/cs- Unfortunately, this hope is false, in both scenarios. In fact, our theorems say that not only 
does CA fail to fulfill this hope, but so does every algorithm. In other words, neither of these scenarios 
is enough to guarantee the existence of an algorithm with optimality ratio independent of cr/cs- In the 



case of the first scenario, we obtain this negative result from Theorem 9.1. In the case of the second 



scenario, we obtain this negative result from Theorem 9.2. 

However, we shall show that by slightly strengthening the assumption on t in the second scenario, 
CA becomes instance optimal, with optimality ratio independent of cr/cs- Let us say that the aggrega- 
tion function t is strictly monotone in each argument if whenever one argument is strictly increased and 
the remaining arguments are held fixed, then the value of the aggregation function is strictly increased. 
That is, t is strictly monotone in each argument if Xi < x'^ implies that 

t (xi , . . . , Xj_i , Xj , Xi^i , . . . , XiYi) 
< t (xi , . . . , Xj_i , Xj , Xj^l , . . . , Xm) . 

The average (or sum) is strictly monotone in each argument, whereas min is not. 



We now show (Theorem 8.9) that in the second scenario above, if we replace "The aggregation 
function t is strictly monotone" by "The aggregation function t is strictly monotone in each argument", 
then CA is instance optimal, with optimality ratio independent of cr/cs- We shall also show (Theo- 
rem 8.1C ) that the same result holds if instead, we simply take t to be min, even though min is not strictly 



monotone in each argument. 
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Theorem 8.9: Assume that the aggregation function t is strictly monotone in each argument. Let D be 
the class of all databases that satisfy the distinctness property. Let A be the class of all algorithms that 
correctly find the top k objects for tfor every database in D. Then CA is instance optimal over A and 
D, with optimality ratio independent ofcn/cs- 

Proof: Assume D G D. Assume that when CA runs on V, it halts after doing sorted access to depth 
d. Thus, CA makes md sorted accesses and r random accesses, where r < md/h. Note that in CA the 
two components {mdcs and rcR) of the cost mdcs + rcR are roughly equal, and their sum is at most 
2mdcs. Assume ^ € A, and that A makes d' sorted accesses and r' random accesses. The cost that A 
incurs is therefore d'cs + r'cR. 

Suppose that algorithm A announces that the objects R[, R2, . . . , R'f, are the top k. First, we claim 
that each R'^ appears in the top d' + r' + 1 objects of at least one list Lj. Suppose not. Then there is an 
object R[ output by A such that in each list there is a vacancy above R'^ that has not been accessed either 
by sorted or random access. There is a database V identical to V in all locations accessed by A but 
with an object R' {R[,R2, . . . , i?^} whose values reside in these vacancies. From the distinctness 
property, for each field the value for R' is strictly larger than that for R'^, and from strict monotonicity 
of t we have t{R') > t{R[), making R' a mandatory member of the output. (Note: we used only strict 
monotonicity of t rather than the stronger property of being strictly monotone in each variable.) This is 
a contradiction. Hence, each R[ appears in the top d' + r' + 1 objects of at least one list Lj. 

Let Sk = min{i(i2']^), t(i?2)) • • • ^t{R'^)}. Define the set C of objects not output by A whose B 
value at step d' + r' + 1 of CA (that is, after d' + r' + 1 parallel sorted accesses) is more than Sk, that is, 

C = {R^ {R[,R'2, R'kW'^'+'-'+'HR) > Sk}. 



We claim that for each object R ^ C, algorithm A must use a random access (to determine i?'s 
value in some hst). Suppose not. Then we show a database V on which algorithm A performs the same 
as on V but where t{R) > Sk- This is a contradiction, since then R would have to be in the output 
of A. For each field i of R that is not accessed by A, we assign in V the highest value from the top 
d' + r' + 1 locations of Lj that had not been accessed by A; such "free" locations exist by the pigeonhole 
principal, since A "touched" at most d' + r' objects. Now each field i of R that is accessed by A is one 
of the top d' values in Li, since by assumption R was accessed only under sorted access by A. Also, by 
construction, in V each remaining field i of i? is one of the top d' + r' + 1 values in Lj. So in V, every 
field i of ii is one of the top d' + r' + 1 values in Lj. Also, by construction, the value of every field i 
of R is at least as high in V as in V. It follows by monotonicity of t that the value of t{R) in V is at 
least B^'^ (R) (we do not need the stronger fact that t is strictly monotone in each argument). But 
Q{d +r +i)(^) > Sk, since R G C. Hence, t{R) > Sk. This is the contradiction that was to be shown. 
So indeed, for each object R € C algorithm A must use a random access. Hence, r' > \C\. 

Set d" = h{\C\ + k) + d' + r' + 1. We now show that CA halts by depth d". There are two cases, 
depending on whether or not the escape clause in Step 2 of CA (which says "If there is no such object, 
then do not do a random access on this step") is invoked at some depth d with d' + r' + 1 < d < d" . 

Case 1: The escape clause of CA is invoked at some depth d with d' + r' + 1 < d < d" . There are 
two subcases, depending on whether or not d' + r' + 1 > k. 

Subcase 1: d' + r' + 1 > k. Then d> d' + r' + 1 > k. Just as in the second paragraph of the proof 
of Theorem 5.1, we know that the algorithm CA has seen at least d objects by depth d (this is because 
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by depth d it has made md sorted accesses, and each object is accessed at most m times under sorted 
access). If CA had seen strictly more than d objects by depth d, then the escape clause would not be 
invoked. Since the escape clause was invoked, it follows that CA must have seen exactly d objects by 
depth d. By depth d, the algorithm CA has made exactly dm sorted accesses. Since CA has seen exactly 
d objects by depth d, and since each object is accessed at most m times under sorted access, it follows 
that each of the d objects that CA has seen has been seen under sorted access in every one of the m lists. 
Since d> k,hy depth d there are at least k objects that have been seen under sorted access in every one 
of the lists. (This situation should sound familiar: it is the stopping rule for FA.) For every object that 
has been seen, there is no uncertainty about its overall grade (since it has been seen in every list), and 
so no object that has been seen and is not in the top A; list is viable. Since each object that has not been 
seen has B^'^^ value at most equal to the threshold value at depth d, and each member of the top k list 
has grade at least equal to the threshold value, it follows that no object that has not been seen is viable. 
So there are no more viable objects outside of the top k list, and CA halts by depth d < d", as desired. 

Subcase 2: d' + r' + 1 < k. So algorithm A sees less than k objects before it halts. If database V 
contains more than k objects, then there are two objects R and R' that algorithm A does not see such 
that algorithm A outputs R but not R! as part of the top k. But then, since algorithm A does not have 
information to distinguish R and R', it must make a mistake on some database (either the database T> or 
the database obtained from T> by reversing the roles of R and R'). So database V caimot contain more 
than k objects. Since we are assuming throughout this paper that the number of objects in the database 
is at least k, it follows that V contains exactly k objects. Therefore, at depth k of algorithm CA, all k 
objects have been seen under sorted access in every list. Similarly to the proof in Subcase I, it follows 
that CA halts at depth k. Since k < d", we know that CA halts by depth d", as desired. 

Case 2: The escape clause of CA is not invoked at any depth d with d' + r' + \ < d < d" . Recall 
that CA performs random access on viable objects based on their B values. Until they receive a random 
access after step d' + r' + 1 of CA, the members of C have the highest B values. Therefore, within 
h\C\ steps after reaching depth d' + r' + 1 (that is, by step d' + r' + \ + h\C\), all members of C will 
be randomly accessed. We now argue that the next objects to be accessed in CA will be the i?-'s that 
are output by A (unless they have been randomly accessed already.) Here we will appeal to the strict 
monotonicity in each argument of the aggregation function t. For a function t that is strictly monotone 
in each argument, at each step of CA on a database that satisfies the distinctness property and for every 
object R, if <S'(-R) is missing some fields, then Bs{R) > t{R). Therefore at step d' + r' + 1 + h\C\ 
of CA, for all R'^ whose t value has not been determined we have > t{R!^ > Sk- 

Since no other object with B^'^ value larger than Sk is left, after at most hk more steps in 

CA, all of {Ri,R2, . . . ,R'k} with missing fields will be randomly accessed and their t value will be 
known to CA. 

We claim that at step d" of CA there are no more viable objects left: first, = Sk, since all 

of {R'l, R2, ■ ■ ■ , R'k} have been accessed (in every field) and each of their W^'^ ^ values equals their t 
values. Since all other objects R with (i?) > Sk have been accessed, there are more viable objects 
left, so CA halts. 

We have shown that in both cases, the algorithm CA halts by depth d". Recall that when CA gets to 
depth d it incurs a cost of at most 2mdcs- We showed that CA halts by depth d" = h{\C\ + k) + d' + 
r' + 1 < h{r' + k) + d' + r' + 1. Hence, the cost CA incurs is at most 2m{h{r' + k) + d' + r' + l)cs. 
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which is 2m{h{r' + k) + d' + r)cs plus an additive constant of 2mcs- Now 

2m{h{r' + k) + d' + r')cs < 2m{—{r' + k)cs + {d' + r')cs) 

= 2m{r'{cR + cs) + d'cs + kcR) 

< 2m{r' {2cr) + d'cs + kcn) since by assumption cr > cs 

< 2m{r' {2cr) + d'cs + kr'cji) since r' > 1 (see below) 
= 2md'cs + (4m + k)r'cR 

< {Am + k){d' cs + r' cr) 

Since d'cs + t'cr is the middleware cost of A, we get that the optimality ratio of CA is at most 4m + k. 

So we need only show that we may assume r' > 1. Assume not. Then A makes no random accesses. 
Now by Theorem |8.5| , NRA is instance optimal compared with algorithms that make no random access, 
and of course the optimality ratio is independent of cr/cs- Further, the cost of CA is at most twice that 
of NRA. So CA is instance optimal compared with algorithms that make no random access, such as A, 
with optimality ratio independent of cr/cs- d 



In the proof of Theorem K% we showed that under the assumptions of Theorem 8.9 (strict mono 



tonicity in each argument and the distinctness property), the optimality ratio of CA is at most 4m + k. 



In Theorem 9.2, we give a lower bound that is linear in m, at least for one aggregation function that is 
strictly monotone in each argument. 

The next theorem says that for the function min (which is not strictly monotone in each argument), 
algorithm CA is instance optimal. 

Theorem 8.10: Let D be the class of all databases that satisfy the distinctness property. Let A be the 
class of all algorithms that correctly find the top k objects for min /or every database in D. Then CA is 
instance optimal over A and D, with optimality ratio independent of cr/cs- 



Proof (Sketch): The proof is similar to the proof of Theorem where the key point is that for the 
function min at every step d of CA there can be at most m different i?'s with the same value, 
smce equals one of the fields of R and the distinctness property assures that there are at most 

m different fields in all lists with the same value (this replaces the use of strict monotonicity in each 
argument). Therefore at step d' + r' + 1 + h\C\ there are at most m objects with B value that equals 
Sk, and there are no objects outside of {R'i,R'2, ■ ■ ■ ,R'k} whose B value exceeds Sk- Since the B 
value of each member of {R'l, R'2, ■ ■ ■ R'^} is at least 5^, it follows that after hm more steps all of 
{R'l, R2, ■ ■ ■ , R'j^} will be randomly accessed, so there will be no viable objects left and CA will halt. 
The rest of the analysis is similar to the proof of Theorem |8.9| , except that hk is replaced by hm. The 
net result is an optimality ratio of at most 5m. □ 



In the proof of Theorem g.lO, we showed that under the assumptions of Theorem 8.10 (the dis 



tinctness property with min as the aggregation function), the optimality ratio of CA is at most 5m. In 



Theorem |9.4| , we give a lower bound that is linear in m. 



8.4 CA Versus Other Algorithms 

In this section, we compare CA against two other algorithms. The first algorithm we compare it against 
is the intermittent algorithm, which does random accesses in the same time order as TA does, but 
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Figure 5: Database about CA versus the intermittent algorithm 



simply delays them, so that it does random accesses every h = [cji/csl steps. The second algorithm 
we compare CA against is TA. 

CA versus the intermittent algorithm: We now consider the choice we made in CA of doing 
random access to find the fields of the viable object R whose B^'^'l value is the maximum. We compare 
its performance with the intermittent algorithm, which we just described. We show a database (see 
Figure ||) where the intermittent algorithm does much worse than CA. Consider the aggregation function 
t where t(xi, X2, 2:3) = xi + X2 + X3. Let cr/cs be a large integer. Let P be a database where the top 
h — 2 locations in Li and L2 have grades of the form 1/2 + i/(8/i), for 1 < i < /i — 2, and where none 
are matched with each other. Location h — lm the two lists belong to same object R, with grade 1/2 in 
both of them. Location h in the two lists both have the grade 1/8. In L3 the top h? — 1 locations have 
grades of the form 1/2 + i/{Sh?), for 1 < i < h? — 1, and in location h?, object R has grade 1/2. Note 
that the maximum overall grade (which occurs for the object i?) is 1^ and that all objects that appear in 
one of the top h — 2 locations in lists Li and L2 have overall grades that are at most l| (this is because 
each object in the top h — 2 locations in Li has grade at most 5/8 in Li, grade at most 1/8 in L2, and 
grade at most 5/8 in L3.) At step h in CA we have that B^^\R) > 1^, whereas for all other objects 
their i?^^) value is at most l|. Therefore on this database, CA performs h sorted accesses in parallel 
and a single random access on R and then halts. Its middleware cost is therefore hcs + cr = 2cr. The 
intermittent algorithm, on the other hand, does not give priority to checking R, and will first do two 
random accesses for each of the h — 2 objects at the top of each of the three lists. Since we take all of 
these objects to be distinct, this is 6{h — 2) random accesses, with a middleware cost of 6{h — 2)cr. 
So the ratio of the middleware cost of the intermittent algorithm to the middleware cost of CA on this 
database is at least 3{h — 2), which can be arbitrarily large. 

In particular. Theorem would be false if we were to replace CA by the intermittent algorithm, 
since this example shows that the optimality ratio of the intermittent algorithm can be arbitrarily large 
for h arbitrarily large. 

CA versus TA: It is intriguing to consider the differences between CA and TA, even when cr/cs 
is not large. Intuitively, TA beats CA in terms of sorted accesses, and CA beats TA in terms of random 
accesses. More precisely, TA never makes more sorted accesses than CA, since TA gathers as much 
information as it can about every object it encounters under sorted access. On the other hand, if we 
focus on random accesses, then we see that TA does random access to every field of every object that 
it sees under sorted access. But CA is more selective about its random accesses. It "stores up" objects 
that it has seen under sorted access, and then does random access only for the object in its stored-up 
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collection with the best potential. 

We now consider other advantages of CA over TA. In the database we presented in comparing CA 
with the intermittent algorithm, the random access cost of TA is the same as that of the intermittent 
algorithm. So for this database, the ratio of the middleware cost of TA to the middleware cost of CA is 
at least 3(/i — 2). This is a manifestation of the dependence of the optimality ratio of TA on cr/cs and 
the independence of the optimality ratio of CA on cr/cs- Furthermore, the fact that at least under certain 
assumptions, TA has an optimality ratio that is quadratic in m, whereas under certain assumptions, CA 
has an optimality ratio that is only linear in m, is also an indicator of the possible superiority of CA 
over TA in certain circumstances. This requires further investigation. As an example where it might be 
interesting to compare CA and TA, let the aggregation function be min, let D be the class of all databases 
that satisfy the distinctness property, and let A be the class of all algorithms that correctly find the top 
k objects for min for every database in D. We know that TA and CA are both instance optimal in this 
scenario (Theorems 6^ and 8^), and we know that the optimality ratio of CA is independent of cr/cs 
(Theorem |8.9[ ). What are the precise optimality ratios of TA and C A in this scenario? Which has a better 
optimality ratio when, say, cr = cs"^ 

TA has an important advantage over CA. Namely, TA requires very little bookkeeping, whereas, 
on the face of it, CA requires a great deal of bookkeeping. Thus, in CA, for every sorted access it is 
necessary to update the B value (the upper bound on the overall grade) for every object where not all of 
its fields are known. As we discussed in Remark for NRA, it would be interesting to develop data 
structures for CA that would lead to a reasonable amount of bookkeeping. We could then compare CA 
versus TA in realistic scenarios (both by analysis and simulations). 



9 Lower Bounds on the Optimality Ratio 

In this section, we prove various lower bounds on the optimality ratio, both for deterministic algorithms 
and for probabilistic algorithms that never make a mistake. Each lower bound corresponds to at least 
one theorem from earlier in the paper. 

The next theorem gives a matching lower bound for the upper bound on the optimality ratio of TA 
given in the proof of Theorem ^]T|, provided the aggregation function is strict. As we noted earlier, this 
lower bound need not hold if the aggregation function is not strict (for example, for the aggregation 
function max). 

Theorem 9.1: Let t be an arbitrary monotone, strict aggregation function with m arguments. Let D 
be the class of all databases. Let A be the class of all algorithms that correctly find the top k answers 
for tfor every database and that do not make wild guesses. There is no deterministic algorithm that is 
instance optimal over A and D, with optimality ratio less than m + m{m — 1)cr/cs- 

Proof: We assume first that k = I; later, we shall remove this assumption. We restrict our attention to 
a subfamily D' of D, by making use of positive parameters d,ip,ki,k2 where 

1. d, ki, and k2 are integers. 

2. ip = {dm — l)cs + {dm — l){m — 1)cr. 

3. k2 > ki > max{d,^/cs)- 
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The family D' contains every database of the following form. In every list, the top k2 grades are 1 , and 
the remaining grades are 0. No object is in the top ki of more than one list. There is only one object 
T that has grade 1 in all of the lists, and it is in the top d of one list. Except for T, each object that is 
in the top ki of any of the lists has grade 1 in all but one of the lists, and grade in the remaining list. 
It is easy to see that we can pick ki and ^2 big enough to satisfy our conditions, for a sufficiently large 
number N of objects. 

Let A be an arbitrary deterministic algorithm in A. We now show, by an adversary argument, that 
the adversary can force A to have middleware cost at least on some database in D'. The idea is that the 
adversary dynamically adjusts the database as each query comes in from A, in such a way as to evade 
allowing A to determine the top element until as late as possible. 

Let us say that an object is high in list i if it is in the top d of list i, and high if it is high in some list. 
Since no object is high in more than one list, there are dm high objects. Assume that A sees at most 
dm — 2 high objects, and hence does not see at least two high objects Si and 82- Then the adversary 
can force the answers that A receives to be consistent with either Si or S2 being the top object T. This 
is a contradiction, since A does not have enough information to halt safely, since it does not know the 
identity of the top object. So A must see at least dm — 1 high objects. Since A does not make wild 
guesses, its sorted access cost is at least {dm — l)cs- There are two cases. 

Case 1: Algorithm A sees some high object under sorted access in a list j where it is not high (and 
hence below position ki in list j, since no object can be in the top ki positions in more than one list). 
Then A has sorted access cost more than kics > {4'/cs)cs = i^, as desired. 

Case 2: There is no high object that A sees under sorted access in a list where it is not high. Let 
us say that a high object h is fully randomly accessed if A does random access to h in each of the lists 
where it is not high. Whenever A does random access to a high object in a list where it is not high, then 
the adversary assures that the first m — 2 such random accesses have grade 1 , and only the final such 
random access has grade (this is possible for the adversary to continue until it has done m — 1 random 
accesses for all but one of the high objects). Assume that there are at least two high objects Pi and P2 
that are not fully randomly accessed. Then the adversary can force the answers that A receives to be 
consistent with either Pi or P2 being the top object T. This is a contradiction, since once again, A does 
not have enough information to halt safely. So there is at most one high object that is not fully randomly 
accessed. Since there are dm high objects, it follows that A must make at least {dm — 1) (m — 1) random 
accesses, with a random access cost of {dm — l)(m — l)cij. Hence, the middleware cost of A is at least 
{dm — l)cs + {dm — l)(m — 1)cr = ifj, as desired. 

So in either case, the middleware cost of algorithm A on the resulting database is at least ijj. How- 
ever, there is an algorithm in A that makes at most d sorted accesses and m — 1 random accesses, 
and so has middleware cost at most dcs + (m — l)ci?. By choosing d sufficiently large, the ratio 
(dm- 1 l^^^^'^^^'^J'^^j™ - 1 made as close as desired to m + m{m — l)cFi/cs. The theorem fol- 

lows in the case when k = 1. 

We now describe how to modify the proof in the case when k > I. The idea is that we make k — I 
of the top k objects easy to find. We modify the databases given in the proof above by creating k — I 
new objects, each with a grade of 1 in every list, and putting them at the top of each of the lists. The 
simple details are left to the reader. □ 



In the proof of Theorem |6^ (which assumes strict monotonicity and the distinctness property), we 
showed that the optimality ratio of TA is at most cm^, where c = max {cr/ as, cs/cr}. In the next 
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theorem, we give an aggregation function that is strictly monotone such that no deterministic algorithm 
can have an optimality ratio of less than ^^^^f^- So in our case of greatest interest, where cr > cs, 
there is a gap of around a factor of 2m in the upper and lower bounds. The aggregation function we use 
for this result is the function t given by 

t{xi,X2, . . .,Xm) = min(xi + X2,X3, . . .,Xm) (5) 

The reason we made use of the unusual aggregation function in is that in the case of min (or an 
aggregation function such as average that is strictly monotone in each argument), there is an algorithm 
(algorithm CA of Section with optimality ratio independent of cr/cs when we restrict our attention 
to databases that satisfy the distinctness property. Thus, the negative result of the next theorem does not 
hold for min or average. 



Theorem 9.2: Let the aggregation function t be given by above. Let D be the class of all databases 
that satisfy the distinctness property. Let A be the class of all algorithms that correctly find the top k 
objects for tfor every database in D. There is no deterministic algorithm that is instance optimal over 
A and D, with optimality ratio less than ^^^g^f^- 



Proof: As in the proof of Theorem |9JJ, we can assume without loss of generality that k = I. We restrict 



our attention to a subfamily D' of D, by making use of positive parameters d, N, and ip, where 

1 . d and N are integers. 

2. i; = {d - l)im - 2)cR. 

3. N > m.ax{d, Aip/cs), and is a multiple of 4. 

The family D' contains each database of the following form. There are A^ objects. The top d grades in 
lists 1 and 2 are of the form i/{2d + 2) for 1 < i < d, and the object with grade i/{2d + 2) in list 1 is 
the one with the grade {d+1 — i)/ (2d + 2) in list 2. Hence, the xi + X2 value of these d objects is 1/2. 
The grades in the other lists are of the form i/N, for 1 < i < N. One of the top d objects in lists 1 and 
2 has a grade in the half-closed interval |) in each of the other lists. All the rest of the top d objects 
in hsts 1 and 2 have a grade in the half-closed interval |) in all but one of the other lists, and a grade 
in the open interval (0, ^) in the remaining list. The top object, which we call T, is the unique object 
whose overall grade is 1/2. Since T has grade less than 3/4 in lists 3, . . ., m, it occurs after the first 
A^/4 objects in each of these m — 2 lists. Furthermore, simply based on the grades of the top d objects 
in lists 1 and 2, it is clear that the top object has grade at most 1/2. 

Let A be an ai^bitrary deterministic algorithm in A. We now show, by an adversary argument, that 
the adversary can force A to have middleware cost at least ijj on some database in D'. The idea is that the 
adversary dynamically adjusts the database as each query comes in from A, in such a way as to evade 
allowing A to determine the top element until as late as possible. There are two cases. 

Case 1: A does at least A^/4 sorted accesses. Then the sorted access cost of A is at least {N/4)cs > 
{'4>/cs)cs = ip, as desired. 

Case 2: A does less than A^/4 sorted accesses. Let us call the top d objects in lists 1 and 2 candi- 
dates. Thus, A does not see any candidate under sorted access in any of the lists 3, . . . , m. Let us call a 
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grade that is at least 1/2 high, and a grade less than 1/2 low. Let us say that a candidate S is fully ran- 
domly accessed if A does random access to S in each of the lists 3, . . . , m. Whenever ^ does random 
access to a candidate in at least one of lists 3, . . . , m, then as long as possible, the adversary assures that 
the first m — 3 random accesses have a high grade, and that only the final random access has a low grade 
(it is possible for the adversary to continue like this until all but one of the candidates is fully randomly 
accessed). Assume that there are at least two candidates Pi and P2 that are not fully randomly accessed. 
Then the adversary can force the answers that A receives to be consistent with either Pi or P2 being the 
top object T. This is a contradiction, since A does not have enough information to halt safely. So there 
is at most one candidate that is not fully randomly accessed. 

Since there are at least d — I candidates that are fully randomly accessed, and hence each have at 
least m — 2 random accesses, the random access cost of A is at least [d — l)(m — 2)cr. Hence, the 
middleware cost of A is at least {d — l)(m — 2)cr = ij), as desired. 

So in either case, the middleware cost of algorithm A on the resulting database is at least V'- How- 
ever, there is an algorithm in A that accesses the top d objects in lists 1 and 2, and then makes a random 
access to object T in each of lists 3, . . ., m. Its middleware cost is 2dcs + {m — 2)cr. By choosing 
d sufficiently large, the ratio ^^i^^^^^^ly^ can be made as close as desired to ^^^fj- The theorem 
follows. □ 

The next theorem is somewhat redundant (except for the fact that it deals with probabilistic algo- 
rithms), because of Theorem pH] . We give it because its proof is simple, and because we generalize the 
proof in the theorem following it. 

Theorem 9.3: Let t be an arbitrary monotone, strict aggregation function with m arguments. Let D 
be the class of all databases. Let A be the class of all algorithms that correctly find the top k answers 
for t for every database and that do not make wild guesses. There is no deterministic algorithm ( or 
even probabilistic algorithm that never makes a mistake) that is instance optimal over A and D, with 
optimality ratio less than m/2. 



Proof: As in the proof of Theorem 9.1, we can assume without loss of generality that k = I. We now 
define a family of databases, each with m sorted lists. There is a parameter d. The top dm values in 
each of the lists is 1 , and all remaining values are 0. There is only one object T that has a value of 1 
in more than one of the lists, and this object T has value 1 in all of the lists. Therefore T has overall 
grade 1, and every other object has overall grade 0. Suppose that T has position d in one of the lists, 
and position dm in all of the other lists. 

Let A be an arbitrary deterministic algorithm in A. Consider the following distribution on databases: 
each member is as above, and the list where T appears in position d is chosen uniformly at random. It 
is easy to see that the expected number of sorted accesses under this distribution of algorithm A is at 
least {dm + l)/2. Since there must be some database where the number of sorted accesses is at least 
equal to the expected number of sorted accesses, the number of sorted accesses on this database is at 
least {dm + l)/2, and so the middleware cost of A on the resulting database is at least {dm + 1)05/2. 
However, there is an algorithm in A that makes d sorted accesses and m — 1 random accesses, and so 
has middleware cost dcs + {m — 1)cr. By choosing d sufficiently large, the ratio J'^^^^^^j^^ can be 
made as close as desired to m/2. The theorem follows (in the deterministic case). 

In the case of probabilistic algorithms that never makes a mistake, we conclude as in the conclusion 



of the proof of Theorem 6.4. □ 
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In the proof of Theorem g.lO , we showed that under the assumptions of Theorem 8.10 (the distinct- 
ness property with min as the aggregation function), the optimality ratio of CA is at most 5m. The next 
theorem gives a lower bound that is linear in m. 



Theorem 9.4: Let D be the class of all databases that satisfy the distinctness property. Let A be the 
class of all algorithms that correctly find the top k answers for min for every database. There is no 
deterministic algorithm (or even probabilistic algorithm that never makes a mistake) that is instance 
optimal over A and D, with optimality ratio less than m/2. 



Proof: The proof is obtained from the proof of Theorem by modifying the construction slightly to 
guarantee that we consider only databases that satisfy the distinctness property. The simple details are 
left to the reader. □ 

The next theorem gives a matching lower bound for the upper bound on the optimality ratio of NRA 



given in the proof of Theorem 8.4, provided the aggregation function is strict. 



Theorem 9.5: Let t be an arbitrary monotone, strict aggregation function with m arguments. Let D be 
the class of all databases. Let A be the class of all algorithms that correctly find the top k objects for t 
for every database and that do not make random accesses. There is no deterministic algorithm that is 
instance optimal over A and D, with optimality ratio less than m. 



Proof: As in the proof of Theorem 9.1, we can assume without loss of generality that k = 1. We restrict 
our attention to a subfamily D' of D, by making use of a positive integer parameter d. The family D' 
contains every database of the following form. 

There are 2m special objects Ti, . . . , Tm, T[, . . . , T^. There is only one object T in the database 
with a grade of 1 in every list, and it is one of the 2m special objects. Thus, the top object T is one of 
the special objects. For each i, let us refer to list i as the challenge list for the special objects Tj and T/. 
For each i, the top 2m — 2 objects in list i are precisely the special objects except for Ti and T/. Thus, 
no special object is in the top 2m — 2 of its challenge list, but all of the other special objects are. The 
top d objects in each list have grade 1, and every remaining object in each list has grade 0. If T = Tj or 
T = T/, then T is in position d in list i. Thus, the unique top object is at position d in some list. Note 
that each special object is at or below position d in its challenge list, and exactly one special object (the 
top object) is at position d in its challenge list. 

Let A be an arbitrary deterministic algorithm in A. We now show, by an adversary argument, that 
the adversary can force A to have sorted access cost at least dm on some database in D'. The idea is 
that the adversary dynamically adjusts the database as each query comes in from A, in such a way as to 
evade allowing A to determine the top element until as late as possible. 

The first m— 1 times that algorithm A reaches position d in a list, the adversary forces A to encounter 
some object that is not special in position d. Thus, the first time that the adversary allows algorithm A 
to encounter a special object after position 2m — 2 is at position d of the last list i that it accesses to 
depth d. Only at that time does the adversary allow the algorithm to discover which of Tj or T/ is the 
top object. 

It is clear that the sorted access cost of A on this resulting database is at least dm. However, there is 
an algorithm in A that makes at most d sorted accesses to one list and 2m — 2 sorted accesses to each of 
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Table 1: Summary of Upper and Lower Bounds 



the remaining lists, for a total of at most d + {m — l)(2m — 2) sorted accesses, and so has middleware 
cost at most (d + (m — l)(2m — 2))cs. By choosing d sufficiently large, the ratio (^_|_(,^J^[)'(2lm-2)cg 
can be made as close as desired to m. The theorem follows. □ 



9.1 Summary of upper and lower bounds 

Table [T] summarizes our upper and lower bounds. The rows correspond to the different restrictions on the 
set A of algorithms, and the columns to the restrictions on the set D of databases and on the aggregation 
function t. Note that "SM" means "strictly monotone" and "SMV" means "strictly monotone in each 
variable." "Distinctness" means that D is the collection of databases that satisfy the distinctness property. 
Note also that c = max ^}. For each such combination we provide our upper and lower bounds, 
along with the theorem where these bounds are proven. The upper bounds are stated above the single 
separating lines and the lower bounds are below them. (The upper bounds are stated explicitly after the 
proofs of the referenced theorems.) The lower bounds may be deterministic or probabilistic. 



10 Related Work 



Nepal and Ramakrishna [?] define an algorithm that is equivalent to TA. Their notion of optimality is 
weaker than ours. Further, they make an assumption that is essentially equivalent to the aggregation 
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function being the min.[^ 

Giintzer, Balke, and Kiessling [?] also define an algorithm that is equivalent to TA. They call this 
algorithm "Quick-Combine (basic version)" to distinguish it from their algorithm of interest, which they 
call "Quick-Combine". The difference between these two algorithms is that Quick-Combine provides a 
heuristic rule that determines which sorted list Lj to do the next sorted access on. The intuitive idea is 
that they wish to speed up TA by taking advantage of skewed distributions of grades.|^ They make no 
claims of optimality. Instead, they do extensive simulations to compare Quick-Combine against FA (but 
they do not compare Quick-Combine against TA). 

We feel that it is an interesting problem to find good heuristics as to which list should be accessed 
next under sorted access. Such heuristics can potentially lead to some speedup of TA (but the number 
of sorted accesses can decrease by a factor of at most m, the number of lists). Unfortunately, there 
are several problems with the heuristic used by Quick-Combine. The first problem is that it involves 
a partial derivative, which is not defined for certain aggregation functions (such as min). Even more 
seriously, it is easy to find a family of examples that shows that as a result of using the heuristic, Quick- 
Combine is not instance optimal. We note that heuristics that modify TA by deciding which list should 
be accessed next under sorted access can be forced to be instance optimal simply by insuring that each 
list is accessed under sorted access at least every u steps, for some constant u. 

In another paper, Giintzer, Balke, and Kiessling [?] consider the situation where random accesses 
are impossible. Once again, they define a basic algorithm, called "Stream-Combine (basic version)" 
and a modified algorithm ("Stream-Combine") that incorporates a heuristic rule that tells which sorted 
list Li to do a sorted access on next. Neither version of Stream-Combine is instance optimal. The 
reason that the basic version of Stream-Combine is not instance optimal is that it considers only upper 
bounds on overall grades of objects, unlike our algorithm NRA, which considers both upper and lower 
bounds. They require that the top k objects be given with their grades (whereas as we discussed, we do 
not require the grades to be given in the case where random accesses are impossible). Their algorithm 
cannot say that an object is in the top k unless that object has been seen in every sorted list. Note 
that there are monotone aggregation functions (such as max, or more interestingly, median) where it is 
possible to determine the overall grade of an object without knowing its grade in each sorted list. 

Natsev et al. [?] note that the scenario we have been studying can be thought of as taking joins over 
sorted lists where the join is over a unique record ID present in all the sorted lists. They generalize by 
considering arbitrary joins. 

11 Conclusions and Open Problems 

We studied the elegant and remarkably simple algorithm TA, as well as algorithms for the scenario where 
random access is impossible or expensive relative to sorted access (NRA and CA). To study these algo- 
rithms, we introduced the instance optimality framework in the context of aggregation algorithms, and 

The assumption that Nepal and Ramakrishna make is that the aggregation function t satisfies the lower bounding prop- 
erty. This property says that whenever there is some i such that Xi < x'j for every j, then t{xi, . . . , Xm) < t{x'i, . . . , x'^). 
It is not hard to see that if an aggregation function t satisfies the lower bounding property, then t{xi, . . . , Xm) = 
/(min {xi , . . . , Xm}), where f{x) = t{x, . . . ,x). Note in particular that under the natural assumption that t{x, . . . ,x) — x, 
so that f{x) = X, we have t{xi, . . . , Xm) = min {xi, . . . , Xm}- 

"They make the claim that the optimality results proven in [?] about FA do not hold for a skewed distribution of grades, 
but only for a uniform distribution. This claim is incorrect: the only probabilistic assumption in [?] is that the orderings given 
by the sorted lists are probabilistically independent. 
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provided both positive and negative results. This framework is appropriate for analyzing and comparing 
the performance of algorithms, and provides a very strong notion of optimality. We also considered 
approximation algorithms, and provided positive and negative results about instance optimality there as 
well. 

Open problems: Let us say that an algorithm is tightly instance optimal (over A and D) if it is 
instance optimal (over A and D) and if its optimality ratio is best possible. Thus, Corollary ^3] says 
that NRA is tightly instance optimal, and Corollary says that in the case of no wild guesses and a 
strict aggregation function, TA is tightly instance optimal. In the case of no wild guesses, for which 
aggregation functions is TA tightly instance optimal?[^ What are the possible optimality ratios? For the 
other cases where we showed instance optimality of one of our algorithms (as shown in Table |l|), is the 
algorithm in question in fact tightly instance optimal? For cases where our algorithms might turn out 
not to be tightly instance optimal, what other algorithms are tightly instance optimal? 

There are several other interesting lines of investigation. One is to find other scenarios where in- 
stance optimality can yield meaningful results. Another is to find other applications of our algorithms, 
such as in information retrieval. We already mentioned (Remai^k i.l and Section 8.4) the issue of finding 
efficient data structures for NRA and CA in cases of interest, and of comparing CA versus TA. 
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As noted earlier, when the aggregation function t is max, which is not strict, TA is tightly instance optimal, with optimality 
ratio m. Similarly, when t is a constant, TA is tightly instance optimal, with optimality ratio 1. There are aggregation functions 
where TA is not tightly instance optimal. For example define t by letting t{xi, . . . , Xm) = min(a::i, X2)- It is not hard to see 
that TA is not tightly instance optimal for this choice of t when m > 3. 
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